Bounce Security is a software security consulting boutique, but not a traditional one. As a software developer, security architect, and team/project lead, I've had decades of experience. I've gained (and forgotten) a ridiculous amount of technical knowledge and theory. Most importantly, I've learned expertise in understanding the business's underlying security needs, and how this relates to the actual business goals. I've learned that ultimate security is actually not the best security, but we need to be aiming at efficient, usable security that integrates and scales naturally throughout our processes. I've spent many years consulting to some of the biggest organizations and smallest startups on their application security, and always managed to build an effective security program that actually works for their needs, in their context. I founded Bounce Security to focus on bringing my own brand of efficient, value-driven software security to a wider range of technology companies and software developers. I am *obsessed* with maximizing value output from security efforts. We do things differently from most security consulting companies, and that's a good thing. I am also a frequent speaker and trainer at industry conferences, such as OWASP, RSA, BSides, and InfoSec, as well as developer conferences such as O’Reilly, DevSecCon, PyCon, and DevOpsDays. I've trained many hundreds (is it thousands by now?) of developers on security, including secure coding, security architecture, threat modeling, and more. -----------Specialties: Analyzing and developing quality software systems, focusing mainly on software security. Software security strategy.Development processes, such as SDL and otherwise. Threat modeling complex systems, and training others to do so as well. Enterprise architecture, focusing mainly on identity and access management.
Listed skills include Application Security, Penetration Testing, Information Security, Computer Security, and 46 others.