I am motivated, innovative and communicative. I have a security and systems software development background in consumer electronics and development tools such as compilers, build systems and quality control.In my current position I have built and lead the information security team for a digital health startup. I have introduced initiatives across the board, building a security culture in the organisation, introducing DevSecOps (OWASP SAMM, pen-testing, threat models, static analysis), security monitoring SIEM/SOC, incident response, technical and organisational controls based on ISO 27001 such as vendor management, change management and vulnerability management. As a result the company has been able to obtain and maintain SOC2 Type 2 and HIPAA certifications in in addition to maintaining a high level of GDPR compliance. This role involves reporting to executive level, managing a team & budget, sourcing tools & capabilities, liaising across all business functions, maintaining the information security risk register and supporting the business goals. My background is standards oriented and technical; in the beginning of my career working with the C++ standards committee developing static analysis software for security, later with PKI standards to develop identity management systems based on public key cryptography and more recently Software as a Service architectures in public cloud (predominantly AWS with some GCP). I have significant experience with technologies such as linux, docker, node, C++, lambdas, IAM and networks. I hold an MSc from Trinity College Dublin where my research project was in instruction selection for embedded platforms. My undergraduate degree had a large focus on compilers and cryptography. Throughout my career I have worked with cyber security processes and technology to achieve accredited, secure, hardened and tamper resistant products.
Listed skills include C++, Software Development, Software Engineering, Programming, and 20 others.