About

About

Application & Product Security Engineer

I’m a cybersecurity professional specializing in application and product security, secure software development, and DevSecOps. I bring principal-level software engineering experience to security problems, translating risk into secure architecture, automated guardrails, and fixes that engineering teams can ship.

My work spans application security, cloud security, threat research, incident response, and developer enablement. I’m most effective at the intersection of security and engineering: identifying risk, designing practical controls, and helping teams implement them without bringing delivery to a halt.

I bring more than a decade of Ruby and Python experience across web security, threat research, incident response, and cloud security.

Put simply: I build security into applications, delivery pipelines, and cloud environments.

How I create leverage

Application and product security

I work with engineering teams on authentication and authorization, secure architecture, threat modeling, secure coding, focused application-security reviews, and vulnerability remediation. My goal is to turn a security concern into an explicit product behavior, an implementable design, and evidence that the control works.

Secure delivery and cloud security

I integrate security into the way software is built and operated: secure SDLC practices, CI/CD guardrails, SAST, DAST, software composition analysis, secrets and infrastructure-as-code scanning, software supply-chain controls, AWS security, and practical automation. I favor supported paved roads that make the secure choice easier for developers.

Threat detection and response

My supporting breadth includes threat research, incident readiness, detection engineering, SIEM architecture, network security monitoring, and forensics. That perspective helps me design applications and telemetry for the questions responders will need to answer under pressure.

Security leadership

I lead through clear outcomes, strong technical decisions, and the growth of other people. That means creating usable interfaces between analysts and developers, separating time-sensitive response from planned improvement, turning recurring problems into shared platforms or patterns, and giving leaders evidence they can use to make risk and investment decisions.

Professional experience

Nightwing

Principal Software Engineer
Application & Product Security · Secure SDLC · DevSecOps

  • Strengthen high-risk application controls, including authentication, authorization, session management, and input handling.
  • Embed security testing and policy enforcement into delivery pipelines so teams receive repeatable feedback before release.
  • Partner with software and platform teams on threat modeling, secure architecture, remediation, and AWS security controls.
  • Build security tooling and automation that make secure practices easier to adopt and operate.
  • Establish secure coding guidance, review practices, and developer enablement across engineering work.

RTX

Principal Application Security Engineer
Application Security · Security Automation · Cloud Hardening

  • Guided teams through security authorization work and translated control expectations into engineering tasks and evidence.
  • Improved application and cloud security through repeatable assessment, vulnerability detection, and remediation workflows.
  • Automated security checks and reporting to shorten feedback loops and reduce manual effort.

Mandiant

Threat Research Software Engineer
Security Validation · Adversary Research · Research Automation

  • Built security validation and research tooling that helped turn adversary behavior into repeatable technical analysis.
  • Combined software engineering with threat research to improve the scale, consistency, and usefulness of security evidence.

The through-line is cybersecurity: threat research engineering, application security engineering, and principal-level product and application security. Software engineering is the implementation depth that lets me work directly with developers and turn recommendations into production-quality controls.

Credentials and community

  • CISSP, CISM, and OSCP
  • CompTIA Security+, CySA+, PenTest+, and Cloud+
  • CCSK, INE Web Application Penetration Testing, and Certified Cloud Associate
  • Master’s in Cybersecurity and Information Assurance
  • OWASP and FBI InfraGard member
  • Top 100 finalist in the U.S. Cyber Challenge

Selected work

My Security Portfolio organizes practical writing and technical perspective across application and product security, secure delivery and cloud security, threat detection and response, and security leadership. My open-source work is available on GitHub.

Connect

I’m interested in principal application security, product security, security architecture, DevSecOps, secure software engineering, and security engineering leadership roles. Connect with me on LinkedIn or reach me through the contact links on this site.