Senior Product Security Engineer
Building secure software at enterprise scale. DevSecOps programs, AppSec tooling, and cloud security architecture.
What I Deliver
DevSecOps
- CI/CD security gates
- Policy-as-code guardrails
- IaC security scanning
- Pipeline hardening
AppSec Programs
- SAST/DAST/SCA rollouts
- Secure SDLC frameworks
- Threat modeling
- Gen-AI security automation
Cloud Security
- AWS/GCP hardening
- CIS benchmark implementation
- Multi-account strategy
- Runtime protection
Selected Work
Vulnerability Management Program
60% reductionPartnered with 8+ product teams to embed secure-by-design requirements throughout the SDLC and drive a risk-based vulnerability management program across cloud and on-prem estates.
- Integrated Snyk, Tenable, Orca, and Armis with CI/CD pipelines
- Reduced critical vulnerability backlog by 60% in two quarters
- Implemented policy-as-code guardrails cutting review time from days to under 30 minutes
- Hardened multi-cloud environments (AWS & GCP) using Terraform and CIS benchmarks
LLM-Powered Compliance Bot
75% effort savedDesigned and built a RAG-powered Slack bot that automates compliance evidence collection, intelligent report generation, and real-time security alerting.
- Built RAG pipeline for intelligent compliance querying and report generation
- Developed interactive Slack bot with LLM-powered natural language interface
- Integrated with Asana for automated remediation task tracking
- Leveraged AWS Athena to analyze CloudTrail logs and surface anomalies
- Reduced manual compliance effort by 75%
Enterprise SAST/DAST Rollout
120+ engineersLed enterprise-wide security tooling deployment for a medical IoT platform, enabling secure development practices at scale.
- Led SonarQube Enterprise rollout with Terraform HA cluster and CI/CD integration
- Deployed Burp Suite Enterprise with pipeline hooks and DAST triage training
- Enabled 120+ engineers through developer security training sessions
- Achieved 85% DAST scan coverage across 30 repositories
Platform Security Automation
40% to 90% complianceEnhanced security automation for a cloud-native software-defined networking platform delivering managed services to enterprise customers.
- Integrated Black Duck for container and application SCA
- Developed security tools for CI/CD pipeline integration
- Established automated security testing frameworks
- Improved release compliance from 40% to 90%
Experience
- Reduced critical vulnerability backlog 60% via CI/CD tool integration
- Policy-as-code guardrails cut security reviews from days to 30 minutes
- Built RAG-powered compliance bot reducing manual audit work by 75%
- Implemented LLM-based security triage and vulnerability analysis
- Enterprise SonarQube and Burp Suite rollout for 120+ engineers
- Achieved 85% DAST scan coverage across application portfolio
- AWS and web/API security assessments
- Black Duck SCA integration for container security
- Release compliance improved from 40% to 90%
- CI/CD security gate implementation
- Built test automation frameworks (Selenium, Python, TypeScript)
- Vulnerability assessments and internal penetration testing
- CI/CD pipeline configuration and containerized testing
Tech Stack
Security Tooling
Cloud & Infrastructure
Languages & Automation
AI & LLM Engineering
Certifications
OSCP
Offensive Security Certified Professional
CEH
Certified Ethical Hacker
ISTQB
Certified Tester
Let's Talk Security
Looking for a security engineer who ships? Let's discuss how I can help secure your applications and infrastructure.
contact@a3sec.net