Experience
defi SOLUTIONS (Sep 2019 - Present)
Automotive finance software company providing lending platforms to captives, banks, credit unions, and finance companies.
Security Architect (Aug 2021 – Present)
- Designed and implemented a self-service IAM governance model for GitHub Actions to access Azure using federated credentials, eliminating long-lived credentials across CI/CD pipelines
- Built policy-as-code CI gates enforcing Azure RBAC allow-lists, scope limits, federated credential subject claim validation, and naming conventions
- Developed and maintained the organization's AI governance framework: authored AI policies and standards, led security assessments of AI vendors, and implemented associated technical controls
- Database security implementation including TDE, column-level encryption, data masking, sanitization, anonymization, and tokenization; database auditing and access control design
- Application security testing of commercial products using Burp Suite and OWASP ZAP, including validation of findings from external penetration tests
- Security-related planning, research, and input for new technology and architecture initiatives, including weekly meetings with VPs/CIO
- Threat modeling, security process and control design, standards development, and technical audit escalations
- Mentored a team of ~5 security engineers on topics including threat modeling, identity management, security automation, and incident response
- Led weekly lunch-and-learn sessions with hands-on activities covering security concepts and tooling
- Delivered company-wide training on safe AI usage; mentored helpdesk colleagues on security practices
Lead Security Engineer (Sep 2020 – Aug 2021)
- Technical audit participation and evidence provisioning
- Primary POC for potential security incidents
- Post-incident forensic investigation of compromised systems using Malwarebytes Forensic Timeliner
- Configuration and management of SAST and DAST application security tooling, including CI/CD integration
Security Engineer IV (Sep 2019 – Sep 2020)
- Azure security posture analysis, monitoring, and improvement, using tools including Defender for Cloud, Azure Policy, and Sentinel
- Security task automation via PowerShell scripting and Azure Pipelines (CI/CD), including management of application identities and secrets and secure storage via Azure Key Vault
- Virtual security appliance deployment (via IaC), configuration, and operation, including log forwarders and vulnerability scanners
- IAM design, implementation, and administration using SSO, MFA, RBAC, and PIM
- Management and configuration of corporate security tooling including endpoint threat detection, DLP, CASB, and vulnerability scanning
HookBang (Jun 2017 - Sep 2019)
Creative technology studio providing full-service software design and development for brands, agencies, and technology companies.
Advanced Software Engineer (Nov 2018 – Sep 2019)
- Cloud infrastructure codification and deployment via AWS CloudFormation and Ansible
- Jenkins configuration maintenance
- Integration and deployment management, monitoring, and improvement
- Application development and bug fixing in Node.js and Python, including front-end and back-end components
Software Engineer (Jun 2017 – Nov 2018)
- Mobile AR game development with Unity
- Automated software testing via UI and API
- Serverless web app development using Python, AWS Lambda, and API Gateway
- Cloud resource load testing
NetBoundary (Sep 2014 - Jul 2015)
IT Security Analyst
Managed Security Service Provider (MSSP) specializing in log management, intrusion detection/prevention, and firewall management.
- Monitoring security appliances such as IDS/IPS, Log Management, and SIEMs
- Researching and responding to security incidents
- PCI compliance reporting