Skip to content
SecurityStu

Experience

  • 100s of apps
    Global AppSec program

    Director of Application Security at Penguin Random House: strategy, governance, secure SDLC, and Application Security Posture Management across multiple regions.

  • ~80% faster
    AI-assisted MR reviews

    Built a Merge Request Security Bot that auto-approves low-risk changes and explains risky ones, cutting review bottlenecks while keeping the four-eyes principle.

  • < 1 hour
    Threat models

    STRIDE-based threat modeling strategy backed by a custom threat-register MCP server, built to keep sessions focused and fast.

  • AI security in production

    Guardrails in AWS Bedrock, security reviews of Claude Cowork and M365 Copilot, and secure MCP architecture validated across Claude Code, GitHub Copilot, and ChatGPT Enterprise.

Director, Application Security · Penguin Random House

2025 – Present AppSec Leadership · AI Security · Security Automation

Lead the global Application Security program: strategy, governance, secure SDLC, Application Security Posture Management, and AI security across hundreds of applications in multiple regions.

  • Developed an AI-assisted Merge Request Security Bot that runs SAST/SCA on new code, auto-approves low-risk changes, and generates developer-friendly remediation guidance, reducing review bottlenecks by ~80% while maintaining the four-eyes principle.
  • Designed and implemented the enterprise Application Security Posture Management (ASPM) program, unifying SAST, SCA, IaC, container scanning, pen-testing, and manual findings into one workflow with automated risk scoring and routing.
  • Created the threat modeling strategy, including a custom threat-register MCP server that keeps focused STRIDE sessions under an hour while aligning threats to compliance requirements.
  • Lead AI Security oversight: guardrails in AWS Bedrock, security reviews of Claude Cowork and M365 Copilot, a vibe-coding security strategy, and the security architecture for internally developed MCP servers, validated across Claude Code, GitHub Copilot, and ChatGPT Enterprise.

I set the program strategy and still ship the tooling. Most of the automation above started as code I wrote.

Senior Manager, Application Security · Penguin Random House

2024 – 2025 AppSec Leadership · Secure Architecture

Built the application onboarding and security-by-design program: standardized architecture reviews, threat modeling, risk assessments, code and CI/CD security, logging and monitoring, pen-testing, and pre-production approval.

  • Ran regular STRIDE-based threat modeling sessions with development teams, catching security threats during the design phase instead of after release.
  • Developed a Python application to automate integrating applications with the security toolchain, increasing application visibility by 60% and moving security testing earlier in the SDLC.

Manager, Application Security · Penguin Random House

2023 – 2024 Security Automation · Developer Enablement

Led the AppSec function day to day: vulnerability management, security tooling, and developer training.

  • Built an internal ASPM system pulling from 7+ sources with automated aggregation, deduplication, ticketing, and AI-assisted prioritization: triage time down ~80%, remediation time down ~30%.
  • Led technical security training sessions for hundreds of developers, raising the security maturity of the whole engineering org.

Senior Application Security Engineer · Penguin Random House

2022 – 2023 Security Automation · Developer Enablement

Joined PRH to build out hands-on AppSec capability across the SDLC.

  • Introduced SAST and SCA scanning (Snyk), improving vulnerability detection and reducing third-party library vulnerabilities by 80%.
  • Built a Python tool to inventory and scan 100+ WordPress sites and their plugins, flagging vulnerable versions with results visualized in Power BI.

Application Security Engineer · The Aaron's Company

May 2019 – Feb 2022 Cloud Security · Security Automation

First AppSec role. Started as an analyst triaging findings, finished defining cloud security standards and building the automation that made the backlog manageable.

  • Triaged 3,000+ SAST/DAST findings across C#, JavaScript, and .NET applications, working with 10 technology teams.
  • Defined cloud security standards for containerized apps, ensuring consistency across Docker and Kubernetes deployments.
  • Built a Python program that monitored SAST/DAST scans and posted security alerts to Slack, improving visibility across 50+ applications.

Senior Aviation Meteorologist · United States Navy

May 2013 – May 2017 Leadership · Risk Forecasting

Provided specialized aviation weather support for Navy pilots around the world.

  • Where I learned that risk forecasting is a job, discipline is a skill, and hard work compounds. Everything I brought to security started here.

B.B.A., Information Security and Assurance, Kennesaw State University, 2017 – 2020. Straight A’s, Calculus TA, and an AppSec job offer before graduation.