Anton Abashkin Email and Phone Number
Anton Abashkin work email
- Valid
- Valid
Anton Abashkin personal email
- Valid
- Valid
Anton Abashkin phone numbers
Anton Abashkin (CSSLP) is a lead application security engineer with experience in large, complex enterprise environments such as eBay and agile, hypergrowth companies such as Automation Anywhere, where he delivered application / software security at scale and speed.During the past 10 years, he has worked on every aspect of the secure SDLC. This includes training, security requirements management, secure design & architecture review, secure coding & implementation, security testing & pentesting, as well as secure release & deployment. He demonstrates strong leadership and teamwork skills, working with recent hires to improve their understanding of the organization and its technology, or by leading a group of engineers to release a secure product.Anton can help bridge the gap between security, development, and business. He is a competent technologist that feels comfortable sitting down with engineers and diving directly into design & code. Additionally, he has the business and professional skills to communicate clearly with a large number of different stakeholders, driving everybody towards reaching a mutually satisfying solution. Anton feels comfortable and has extensive experience with presenting to large groups of technologists and upper management on a variety of topics.Technologies: Java, Spring, Python, Django, JavaScript/NodeJS, Android, Linux, bash, Selenium, Git, Jenkins, Docker, Kubernetes, DAST (Arachni, ZAP, Burp Suite, IBM AppScan), SAST (semgrep, HP Fortify, FindSecBugs, Veracode), IAST (Contrast), Threat Modeling and Security Requirements Management (SD Elements, IriusRisk), AWS
-
Founder, Application Security Researcher And EngineerAppsec Science, LlcBozeman, Mt, Us
-
Founder, Application Security Researcher / EngineerAppsec Science, Llc Apr 2022 - PresentCurrently: · Designing and implementing an attack surface analysis tool· Acting as a security advisor to companies such as PolyAPI (https://polyapi.io/)Previously:· Researched NoSQL security. Created PoCs (https://github.com/aabashkin/nosql-injection-vulnapp), and custom static analysis rules (https://github.com/returntocorp/semgrep-rules/pull/2585)· Researched low code security (particularly RPA), created PoCs, engineered solutions (https://github.com/robocorp/rpaframework/pull/899/files)Future: Additional low code security research, software security consulting/advising, engineering secure-by-default frameworks and the corresponding static analysis rules to drive adoption, publishing book and course
-
Volunteer Technical ContributorOwasp Foundation Jan 2016 - PresentWakefield, Ma, Us· Primary author of two reference guides for critical security controls: - https://www.owasp.org/index.php/Bean_Validation_Cheat_Sheet - https://www.owasp.org/index.php/Mass_Assignment_Cheat_Sheet· Latest project is a learning tool that can be used by software engineers,application security engineers, and students to improve their knowledge of application security. Content is based off of the OWASP Application Security Verification Standard (ASVS) and learning is enhanced by Anki spaced repetition software: - https://github.com/application-security-projects/owasp-application-security-verification-standard-anki-deck/ -
Senior Software Security EngineerMongodb Oct 2020 - Apr 2022New York, Ny, Us· Designed and implemented secure-by-design library for safely parsing XML and avoiding XXE vulnerabilities· Analyzed the Kubernetes (k8s) security landscape, performed knowledge sharing with security team, delivered a strategic roadmap for securely deploying workloads and presented to the SRE team. Received praise from both teams on account of effective communication and collaboration skills· Created secure coding guidelines with an innovative approach. Presented to entire engineering department as part of a lunch and learn session. Engineering leadership provided positive feedback· Developed custom static analysis rules using semgrep to catch issues that wouldn't be found by a generic SAST tool· Attended regular design/scope review sessions and provided security related advice· Generated threat models for existing and upcoming features· Performed penetration tests on newly released features· Mentored an intern and successfully delivered a security training related project. Received strong positive feedback from all parties involved. Ultimately, intern ended up accepting a full-time offer· Assisted Staff and Lead engineers in conducting numerous hiring interviews. Created an effective, repeatable process to vet candidates -
SabbaticalSelf-Employed Jul 2019 - Oct 2020
-
Lead Application Security EngineerAutomation Anywhere Mar 2017 - Jun 2019San Jose, Ca, Us· Led all application security related efforts at one of the top competitors in the fastest-growing segment of the global enterprise software market (Robotic Process Automation aka RPA)· Worked with managers, directors, and VPs to systemically improve the secure SDLC across the entire organization, from design, to implementation, to testing, to post-release.· Worked with multiple stakeholders, including business, legal, product, engineering, architecture as the security SME to deliver high impact high risk projects such as the new web-based release of the company's flagship product· Performed root cause analysis on wide variety of vulnerabilities (OWASP Top 10, CWE Top 25, and beyond) and recommended appropriate security controls/standards· Enabled engineers to understand and remediate vulnerabilities· Worked with various technology stacks including Java + Spring + Spring Security, PHP + Wordpress, Android, iPhone· Worked in a cloud environment (AWS, Terraform)· Documented secure coding standards· Conducted secure design and architecture reviews for security controls and high risk application components/features· Managed dynamic and static security tools (Veracode, Black Duck)· Established and expanded security champions program, thus embedding security within each product team· Created JIRA dashboards to generate metrics for management review· Designed a novel solution to integrate the company's product with Common Access Card (CAC) authentication for a federal client operating in a high risk environment· Improvements made in the SDLC eventually enabled the company to meet the requirements for "Continuous" status (the highest possible grade) in the Veracode Verified Program, thus improving company reputation and competitiveness (https://www.veracode.com/verified/directory/automation-anywhere)· Received excellent performance reviews, recognized by the company for moving the needle forward in application security -
Family Time + Independent ProjectsSelf-Employed Dec 2016 - Feb 2017· Before moving further in my career I decided to take a quick break to spend time with my family and work on independent projects· Automated Dynamic Security Scanning in CI with Jenkins + TestNG + WebDriver + WAVSEP demo + Arachni: https://github.com/application-security-projects/ci-automation· Application Security Architecture for Modern 4-Tier Web Platforms: https://github.com/application-security-projects/application-security-architecture
-
Application Security Engineer 3Ebay Jun 2011 - Nov 2016San Jose, Ca, Us· Specialized in web applications, microservices, and mobile. Significant experience working in a large, complex, Agile environment while delivering security at scale and speed· Performed root cause analysis on wide variety of vulnerabilities (OWASP Top10, CWE, domain-specific) across different technology stacks (Java + SpringMVC, JavaScript + NodeJS, Drupal, Android)· Worked with multiple stakeholders, including business, legal, product, risk, engineering, architecture as the security SME to deliver high impact high risk projects such as the Public API release (13 new APIs)· Multiple years of hands-on experience working together with engineers to understand and remediate vulnerabilities. Made the AppSec team more visible and engineers more engaged in security · Balanced business and security needs in difficult or uncertain situations · Designed, implemented, and tested the primary web application security framework w/ platform team· Drove secure software requirements research, validation, and management (200+ requirements)· Conducted secure design & architecture risk reviews, generated threat models (30+ projects)· Created, tested, and evangelized secure coding standards across the organization· Engaged in pentesting and security test automation (DevSecOps)· Worked with Quality Engineering (QE) to develop bespoke test cases regular tools cannot handle· Managed dynamic and static security tools (Arachni, ZAP, Burp Suite, AppScan, Fortify, FindSecBugs)· Evaluated and managed Client Reputation (telemetry) and Bot Management type controls · Developed custom interactive security training, created engaging and immersive learning experiences based on real scenarios (delivered to over 1K developers) · Created JIRA dashboards for metrics· Received excellent performance reviews· Awarded the Critical Talent Retention Bonus reserved for top performers -
Security Seminars - Graduate Student ParticipantSecur-It Jun 2011 - Aug 2011"The Summer Experience, Colloquium and Research in Information Technology (SECuR-IT). This is a ten-week paid internship with academic seminars, sponsored by TRUST partners UC Berkeley, Stanford University and San Jose State University with internships located in Silicon Valley and the San Francisco Bay Area."Participated in seminars held at McKesson, Fortinet, and Intuit.
-
Change/Risk Management ConsultantIbm Global Business Services Jun 2009 - Aug 2009Armonk, New York, Ny, UsWorked on developing the telephony infrastructure of the 2010 Census project. Facilitated change management, created technical documentation, engaged in system requirements gathering and testing. Leveraged the Rational Suite (ClearQuest, ReqPro). -
Web DeveloperEnforme Interactive Jun 2008 - Aug 2008Frederick, Md, UsGathered system user requirements for related projects. Debugged and added additional features to company’s employee time-sheet program. Development performed on the .NET platform with ASP, C#, CSS, and Microsoft SQL. -
It AdministratorSequoia Pharmaceuticals, Inc. 2007 - 2008UsSeries of major projects includes: data encryption solution for executive management use, wireless enterprise level security(RADIUS), Honeypot Intrusion Detection System, Open Solaris ZFS fileserver, configuring firewall/VPN, vulnerability auditing, and technical documentation for previously mentioned projects.
Anton Abashkin Skills
Anton Abashkin Education Details
-
Carnegie Mellon UniversityConcentration: Information Security -
Stanford UniversityAdvanced Computer Security -
University Of Maryland - Robert H. Smith School Of BusinessInformation Systems
Frequently Asked Questions about Anton Abashkin
What company does Anton Abashkin work for?
Anton Abashkin works for Appsec Science, Llc
What is Anton Abashkin's role at the current company?
Anton Abashkin's current role is Founder, Application Security Researcher and Engineer.
What is Anton Abashkin's email address?
Anton Abashkin's email address is ab****@****ail.com
What is Anton Abashkin's direct phone number?
Anton Abashkin's direct phone number is +1 (408) 376*****
What schools did Anton Abashkin attend?
Anton Abashkin attended Carnegie Mellon University, Stanford University, University Of Maryland - Robert H. Smith School Of Business.
What skills is Anton Abashkin known for?
Anton Abashkin has skills like Sql, Information Security, Security, Network Security, Java, Penetration Testing, Information Security Management, Computer Security, Application Security, Linux, Pci Dss, Javascript.
Free Chrome Extension
Find emails, phones & company data instantly
Aero Online
Your AI prospecting assistant
Select data to include:
0 records × $0.02 per record
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial