> whoami

Senior Product Security Engineer

Building secure software at enterprise scale. DevSecOps programs, AppSec tooling, and cloud security architecture.

Tampa, FL OSCP Certified 13 Years Experience
60%
Vuln Reduction
75%
Compliance Automated
3000h
Saved Annually
Get In Touch

What I Deliver

DevSecOps

  • CI/CD security gates
  • Policy-as-code guardrails
  • IaC security scanning
  • Pipeline hardening

AppSec Programs

  • SAST/DAST/SCA rollouts
  • Secure SDLC frameworks
  • Threat modeling
  • Gen-AI security automation

Cloud Security

  • AWS/GCP hardening
  • CIS benchmark implementation
  • Multi-account strategy
  • Runtime protection

Selected Work

Vulnerability Management Program

60% reduction

Partnered with 8+ product teams to embed secure-by-design requirements throughout the SDLC and drive a risk-based vulnerability management program across cloud and on-prem estates.

  • Integrated Snyk, Tenable, Orca, and Armis with CI/CD pipelines
  • Reduced critical vulnerability backlog by 60% in two quarters
  • Implemented policy-as-code guardrails cutting review time from days to under 30 minutes
  • Hardened multi-cloud environments (AWS & GCP) using Terraform and CIS benchmarks
Snyk Tenable Orca Terraform AWS GCP

LLM-Powered Compliance Bot

75% effort saved

Designed and built a RAG-powered Slack bot that automates compliance evidence collection, intelligent report generation, and real-time security alerting.

  • Built RAG pipeline for intelligent compliance querying and report generation
  • Developed interactive Slack bot with LLM-powered natural language interface
  • Integrated with Asana for automated remediation task tracking
  • Leveraged AWS Athena to analyze CloudTrail logs and surface anomalies
  • Reduced manual compliance effort by 75%
Python LLM/RAG Slack API Asana API AWS Athena CloudTrail

Enterprise SAST/DAST Rollout

120+ engineers

Led enterprise-wide security tooling deployment for a medical IoT platform, enabling secure development practices at scale.

  • Led SonarQube Enterprise rollout with Terraform HA cluster and CI/CD integration
  • Deployed Burp Suite Enterprise with pipeline hooks and DAST triage training
  • Enabled 120+ engineers through developer security training sessions
  • Achieved 85% DAST scan coverage across 30 repositories
SonarQube Burp Suite Terraform Jenkins GitLab

Platform Security Automation

40% to 90% compliance

Enhanced security automation for a cloud-native software-defined networking platform delivering managed services to enterprise customers.

  • Integrated Black Duck for container and application SCA
  • Developed security tools for CI/CD pipeline integration
  • Established automated security testing frameworks
  • Improved release compliance from 40% to 90%
Black Duck CI/CD Container Security Python

Experience

2023 - Present
Senior Product Security Engineer
  • Reduced critical vulnerability backlog 60% via CI/CD tool integration
  • Policy-as-code guardrails cut security reviews from days to 30 minutes
  • Built RAG-powered compliance bot reducing manual audit work by 75%
  • Implemented LLM-based security triage and vulnerability analysis
2021 - 2022
Senior DevSecOps Engineer
  • Enterprise SonarQube and Burp Suite rollout for 120+ engineers
  • Achieved 85% DAST scan coverage across application portfolio
  • AWS and web/API security assessments
2020 - 2021
Security Automation Engineer
  • Black Duck SCA integration for container security
  • Release compliance improved from 40% to 90%
  • CI/CD security gate implementation
2013 - 2020
QA & Test Automation Engineer
  • Built test automation frameworks (Selenium, Python, TypeScript)
  • Vulnerability assessments and internal penetration testing
  • CI/CD pipeline configuration and containerized testing

Tech Stack

Security Tooling

Snyk Tenable Orca Security SonarQube Burp Suite Enterprise Armis Black Duck Qualys

Cloud & Infrastructure

AWS GCP Terraform Docker Kubernetes

Languages & Automation

Python TypeScript GitHub Actions Jenkins GitLab CI

AI & LLM Engineering

Claude Code OpenAI Codex RAG Pipelines LLM Security Triage

Certifications

OSCP

Offensive Security Certified Professional

CEH

Certified Ethical Hacker

ISTQB

Certified Tester

Let's Talk Security

Looking for a security engineer who ships? Let's discuss how I can help secure your applications and infrastructure.

contact@a3sec.net
Tampa, FL GitHub PGP Key