This kind of person isn't easy to find, because:
- she has to have extensive knowledge about these frameworks
- feel very confident configuring servers
- follow the latest exploits
- perform security reviews
- audit dependencies
and:
- still be able to address vulnerabilities writing elegant code.
I guess it's a lot to ask for, but we had a team mate in the past who did exactly this.