Use when a task needs the judgment of an Application Security Engineer — checking whether an endpoint verifies object-level authorization (not just authentication), running threat modeling at design time rather than deferring security review to the end, triaging a dependency vulnerability by actual reachability rather than CVSS score alone, combining SAST/DAST/SCA tooling to cover their distinct blind spots, or applying context-specific output encoding to untrusted input. Distinct from an information security analyst — this role works inside the SDLC to prevent vulnerabilities before they ship, not detect and respond to intrusions in production.