Director, Application Security · Penguin Random House
2025 – Present AppSec Leadership · AI Security · Security Automation
Lead the global Application Security program: strategy, governance, secure SDLC, Application Security Posture Management, and AI security across hundreds of applications in multiple regions.
- Developed an AI-assisted Merge Request Security Bot that runs SAST/SCA on new code, auto-approves low-risk changes, and generates developer-friendly remediation guidance, reducing review bottlenecks by ~80% while maintaining the four-eyes principle.
- Designed and implemented the enterprise Application Security Posture Management (ASPM) program, unifying SAST, SCA, IaC, container scanning, pen-testing, and manual findings into one workflow with automated risk scoring and routing.
- Created the threat modeling strategy, including a custom threat-register MCP server that keeps focused STRIDE sessions under an hour while aligning threats to compliance requirements.
- Lead AI Security oversight: guardrails in AWS Bedrock, security reviews of Claude Cowork and M365 Copilot, a vibe-coding security strategy, and the security architecture for internally developed MCP servers, validated across Claude Code, GitHub Copilot, and ChatGPT Enterprise.
I set the program strategy and still ship the tooling. Most of the automation above started as code I wrote.
Senior Manager, Application Security · Penguin Random House
2024 – 2025 AppSec Leadership · Secure Architecture
Built the application onboarding and security-by-design program: standardized architecture reviews, threat modeling, risk assessments, code and CI/CD security, logging and monitoring, pen-testing, and pre-production approval.
- Ran regular STRIDE-based threat modeling sessions with development teams, catching security threats during the design phase instead of after release.
- Developed a Python application to automate integrating applications with the security toolchain, increasing application visibility by 60% and moving security testing earlier in the SDLC.
Manager, Application Security · Penguin Random House
2023 – 2024 Security Automation · Developer Enablement
Led the AppSec function day to day: vulnerability management, security tooling, and developer training.
- Built an internal ASPM system pulling from 7+ sources with automated aggregation, deduplication, ticketing, and AI-assisted prioritization: triage time down ~80%, remediation time down ~30%.
- Led technical security training sessions for hundreds of developers, raising the security maturity of the whole engineering org.
Senior Application Security Engineer · Penguin Random House
2022 – 2023 Security Automation · Developer Enablement
Joined PRH to build out hands-on AppSec capability across the SDLC.
- Introduced SAST and SCA scanning (Snyk), improving vulnerability detection and reducing third-party library vulnerabilities by 80%.
- Built a Python tool to inventory and scan 100+ WordPress sites and their plugins, flagging vulnerable versions with results visualized in Power BI.
Application Security Engineer · The Aaron's Company
May 2019 – Feb 2022 Cloud Security · Security Automation
First AppSec role. Started as an analyst triaging findings, finished defining cloud security standards and building the automation that made the backlog manageable.
- Triaged 3,000+ SAST/DAST findings across C#, JavaScript, and .NET applications, working with 10 technology teams.
- Defined cloud security standards for containerized apps, ensuring consistency across Docker and Kubernetes deployments.
- Built a Python program that monitored SAST/DAST scans and posted security alerts to Slack, improving visibility across 50+ applications.
Senior Aviation Meteorologist · United States Navy
May 2013 – May 2017 Leadership · Risk Forecasting
Provided specialized aviation weather support for Navy pilots around the world.
- Where I learned that risk forecasting is a job, discipline is a skill, and hard work compounds. Everything I brought to security started here.