Andrew Thornton

Andrew Thornton Email and Phone Number

Information Security Problem Solver @ The Home Depot
Atlanta, GA
Andrew Thornton's Location
Atlanta, Georgia, United States, United States
Andrew Thornton's Contact Details

Andrew Thornton work email

Andrew Thornton personal email

n/a
About Andrew Thornton

A highly technical information security professional with over twenty years of hands-on experience, skilled at developing and implementing comprehensive technical security solutions and building security programs. Has a strong grasp of technical fundamentals, applying a pragmatic approach to security. Excels in complex, large-scale environments and thrives on challenges; quickly learns new skills and efficiently manages, prioritizes, and executes multiple tasks simultaneously. Uses Python to engage with large language models, leveraging artificial intelligence to tackle security challenges effectively. Employs a thorough understanding of adversarial tools, techniques, and procedures to guide strategic and tactical decisions. Comfortable with both granular technical details and high-level strategic thinking. Well-versed in policy and security frameworks. Open-source advocate.

Andrew Thornton's Current Company Details
The Home Depot

The Home Depot

View
Information Security Problem Solver
Atlanta, GA
Website:
homedepot.com
Employees:
120627
Andrew Thornton Work Experience Details
  • The Home Depot
    The Home Depot
    Atlanta, Ga
  • Cylitic Security
    Chief Security Officer
    Cylitic Security Feb 2019 - Present
    Spearheaded the architectural design and implementation of all technology and product components for a managed detection and response service at a cybersecurity startup as the first hire. • Created MDR platform comprised of Tanium, Cisco Umbrella, Deep Instinct, and other internally built tools, bringing enterprise level capabilities to smaller environments, increasing their security posture. • Implemented entire security stack for securing corporate assets and networks along with customer systems running macOS and Windows operating systems. • Designed and implemented a customer facing portal using python, postgres, and reactjs running in AWS, instrumental in achieving large customer growth. • Created technology to ingest data points used for security posture rating and remediation item identification, giving enterprise customers real time visibility into their partner’s security posture. • Implemented Splunk for data aggregation and correlation of security events, decreasing MTTD. • Uses python to orchestrate and automate security processes, increasing consistency of outcomes. • Makes use of python and multiple Tanium and third party APIs to automate, 
orchestrate, and enhance detection and response activities
  • The Home Depot
    Head Of Cyber Security - Threat Detection And Response Center
    The Home Depot May 2015 - Feb 2019
    Atlanta, Georgia, Us
    Responsible for creating and leading the Threat Detection & Response center at The Home Depot in Atlanta, Georgia. Reported directly to the CISO. Provided technical and strategic direction to multiple groups including threat intelligence, digital forensics, security operations center, incident response and an offensive security team. Briefed Directors, Vice Presidents, C-level staff and Board of Director members on multiple facets of the program. Managed budgeting, procurement, operation, technical and strategic direction of the program.
  • The Home Depot
    Information Security Manager - Offensive Security / Red Team
    The Home Depot Feb 2014 - May 2015
    Atlanta, Georgia, Us
    Created and lead an offensive security team that performed ongoing large scale external, unauthenticated, unannounced testing of the production environment. Choreographed penetration testing from scope creation and analysis to final reporting. Briefed Senior management, to include Vice Presidents and Executive Leaders on security issues that have been identified within their programs. Performed final reviews on all deliverables to include technical validation of findings. Helped technical stakeholders with forming remediation strategies. Partnered with the security operation center to ensure that malicious traffic and host based indications of compromise are identified and responded to quickly and effectively. Acted as a subject matter expert for offensive security topics and remediation steps. Helped set enterprise security priorities.
  • The Home Depot
    Lead Security Engineer - Penetration Testing
    The Home Depot Jul 2013 - Feb 2014
    Atlanta, Georgia, Us
    Ensured that the security posture of one of the largest e-commerce platforms in the world is as strong as possible through performing application security testing and code review. Partnered with business process owners to explain risks and to help balance security controls with functionality. Responsible for project management and delivery of security findings for multiple initiatives. Partnered with developers at all levels to help them understand how to support compliance on a technical level with given regulations. Reviewed code and performed technical assessment prior to production migrations using Burp Proxy along with other tools.
  • United States Department Of Defense
    Information Assurance Officer
    United States Department Of Defense Sep 2009 - Jul 2013
    Washington, Dc, Us
    Performed penetration testing activity against DoD enterprise networks. Responsible for assessing the technical compliance status of multiple programs within the organization against multiple commercial and government compliance regulations to include DIACAP, PCI-DSS and general DoD Technical Implementation Guidance. Ensured that applications were free from common web based vulnerabilities to include those found within the OWASP Top 10. Created a program that was responsible for runtime analysis of iOS applications to determine data how data was handled and secured.
  • Trustwave
    Security Consultant
    Trustwave Nov 2007 - Sep 2009
    Chicago, Illinois, Us
    Worked as a PCI QSA responsible for technical and procedural auditing of a number of fortune 500 companies to determine compliance with the Payment Card Industry Digital Security Standard. Encountered all types of operating systems, network systems and security systems. Reviewed system implementation documentation and configurations for various types of security devices to include firewalls, network and host based intrusion detection devices, load balancers, log aggregation devices, etc. Created reports on compliance. Created and audited security policies for clients.
  • Secureworks
    Security Consultant
    Secureworks Nov 2005 - Nov 2007
    Atlanta, Ga, Us
    Performed web application assessments and penetration tests for large clients in the financial, health care and manufacturing space. Assisted clients with deciphering and mapping given regulations to security practices. Responsible for managing clients, deadlines, process and procedures and delivery. Created new security programs for application security and threat detection.
  • Nci, Inc.
    Sr. Network Security Engineer
    Nci, Inc. Oct 2003 - Nov 2005
    Reston, Va, Us
    Responsible for designing, implementing, and maintaining a security operations center for the aggregation and analysis of events from 14 NNSA sites to include National Labs. Implemented secured systems and the policies and procedures for the creation of those systems. Implemented large SIEM instances in all Linux environments. Performed incident response on multiple high visibility security breaches.
  • Nci, Inc.
    Sr. Network Security Engineer
    Nci, Inc. Sep 1999 - Oct 2003
    Reston, Va, Us
    Assessed the external security posture of regional headquarters for Department of Defense activity to include application security analysis. Created, deployed and audited firewall access lists, reviewed security device logs and reported findings detailing possible malicious or abusive activities. Researched and presented emerging security technologies to government officials. Tracked compliance with various regulations and reported monthly to Sr. leadership. Performed incident response.

Andrew Thornton Skills

Pci Dss Unix Penetration Testing Cissp Information Security Computer Security Firewalls Vulnerability Assessment Application Security Vulnerability Management Web Application Security Security Architecture Design Ids Incident Response Ips Network Security Security Information Security Management Intrusion Detection Information Assurance Python Django Apache Web Applications Security Audits Web Application Security Assessment Webinspect Pci Standards Payment Industry Payment Systems Security Awareness Payment Card Industry Data Security Standard Nginx Burp Suite Webscarab Vulnerability Scanning Tanium

Frequently Asked Questions about Andrew Thornton

What company does Andrew Thornton work for?

Andrew Thornton works for The Home Depot

What is Andrew Thornton's role at the current company?

Andrew Thornton's current role is Information Security Problem Solver.

What is Andrew Thornton's email address?

Andrew Thornton's email address is an****@****pot.com

What skills is Andrew Thornton known for?

Andrew Thornton has skills like Pci Dss, Unix, Penetration Testing, Cissp, Information Security, Computer Security, Firewalls, Vulnerability Assessment, Application Security, Vulnerability Management, Web Application Security, Security Architecture Design.

Who are Andrew Thornton's colleagues?

Andrew Thornton's colleagues are Rodolfo Godoy, Janice Mullins, Guy Hawkshaw, Pam Erwin, 何去何, Kyle Courtney, Steve Sun.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.