David C.
AeroLeads people directory · profile

David C. Email & Phone Number

Senior Application Security Engineer at SS&C Technologies
Location: Pleasanton, California, United States 5 work roles 3 schools
1 work email found @scif.com LinkedIn matched
✓ Verified July 2026 4 data sources Profile completeness 100%

Contact Signals · 1 work email

Work email y****@scif.com
LinkedIn Profile matched
3 free lookups remaining · No credit card
Current company
Role
Senior Application Security Engineer
Location
Pleasanton, California, United States

Who is David C.? Overview

A concise factual answer block for searchers comparing this professional profile.

Quick answer

David C. is listed as Senior Application Security Engineer at SS&C Technologies, based in Pleasanton, California, United States. AeroLeads shows a work email signal at scif.com and a matched LinkedIn profile for David C..

David C. previously worked as Application Security Engineer at Savvymoney and Security Analyst at State Compensation Insurance Fund. David C. holds Master'S Degree, Computer And Information Systems Security/Information Assurance from Penn State College Of Information Sciences And Technology.

Company email context

Email format at SS&C Technologies

This section adds company-level context without repeating David C.'s masked contact details.

*@scif.com
68% confidence

AeroLeads found 1 current-domain work email signal for David C.. Compare company email patterns before reaching out.

Profile bio

About David C.

Experienced Information Security Specialist with a passion for governance, risk assessment, compliance, software security, IT audit, reporting, privacy, and data protection for financial institutions. Strong technical and communication skills, dedicated to building successful relationships with stakeholders. Industry certified with CISSP, CISM, and CISA. Excited to continue making a positive impact in the dynamic field of information security.

Listed skills include Cisa, Nikto, Computer Forensics, Information Security, and 37 others.

Current workplace

David C.'s current company

Company context helps verify the profile and gives searchers a useful next step.

SS&C Technologies
Ss&C Technologies
Senior Application Security Engineer
AeroLeads page
5 roles

David C. work experience

A career timeline built from the work history available for this profile.

Senior Application Security Engineer

Current

Windsor, Ct, Us

• Assist the Head of Global Application Security and CISO in developing an application security organization capable of scaling to the dimensions of the global 25K+ people company and handling applications involving high financial stakes and matching levels of technical innovation and business complexity, as well as the diverse dev culture resulting from SS&C’s M&A activity.• Emphasis on shifting security left, automation of security testing, security-as-code, laying down safety guardrails, and making threat modeling an integral part of the SSDLC. This includes implementing robust governance for generative AI, providing guardrails for secure and compliant use of LLM models. By managing risks like prompt injections, PII exposure, and hallucinations, we ensure every AI interaction is secure and aligned with business needs.• Ensure the SSDLC follows the global information security and privacy policies and strategies, initiates necessary compliance programs and changes in the global SSDLC realm.• Research threats and attack vectors that may impact SS&C’s web, enterprise, and mobile applications and infrastructure. Stay up-to-date with current offensive and defensive tactics, techniques, and procedures.• Advice engineering teams with the configuration, tuning, and operation of SAST and DAST tools, and their integration into the development process.• Validate and interpret SAST, DAST, bug bounty program, and penetration test findings, demonstrate identified vulnerabilities, assess risks, evaluate possible fixes, and verify successful remediation.• Create and deliver training for engineering team members on secure code development and other security literacy topics.• Develop and collect metrics to measure the success of the application security program.

May 2022 - Present

Application Security Engineer

Dublin, California, Us

• Development and design of security architecture in SavvyMoney• Develop an understanding of the architecture of systems with current security issues and risks• Leads security analysis in SavvyMoney utilizing trends, threat analysis, and current business understanding. From this analysis diagnose or make recommendations for security improvements and risk mitigation• Provide cost-effective architecture recommendations to support the security system’s growth, maintain stability, and provide a good user performance experience• Build and own SavvyMoney’s application security program:• include 1) application threat modeling, 2) a risk acceptance process, 3) a process to approve and manage open source libraries, and 4) secure coding standards that are based on industry-accepted best practices to address common coding vulnerabilities for both internal and Internet-facing applications.• Work with management and DevOps staff to build a new SDLC with different tracks and testing requirements based on utility• Work with management, DevOps staff, and developers to integrate security testing checkpoints in the SDLC• Work with DevOps staff to build the “Sec” in DevSecOps.• Perform manual and automated application security tests • work with developers to reduce or eliminate coding insecurities and exploit vectors.• As the release candidate gatekeeper, own GO, NO GO decisions that are based on a documented• Maintain an accurate inventory of open-source libraries baked in the SavvyMoney code base, tracking• Build an application security toolbox that includes both DAST and SAST technologies and manual vulnerability scanning and penetration testing tools to support SavvyMoney’s continuous integration and deployment operations.• Participate in security monitoring, incident response, and investigations, particularly in the AWS Cloud environment.

Mar 2021 - May 2022

Security Analyst

Sacramento, California, Us

• Acted as a lead resource to users and department managers seeking more information security information.• Collaborated with stakeholders to operate security controls that comprise the GRC program.• Coached 3 junior members.• Conducted over 350 risk assessments (50% involving SOC2 Type II and Cloud) and provided mitigation recommendations.• Conducted over 100 architectural risk analyses, threat modelings, and vulnerabilities management in the SDLC cycle according to OWASP. Vetted the SAST, DAST, IAST, and pen-testing tools used in the SDLC/DevOps/CI/CD processes.• Prepareed and periodically updated information security policies, architectures, and standards per ISO27002/NIST/PCI/HIPAA• Maintained and developed security matrix and KPIs for security programs and software development.• Installed and supported security technologies such as IDS, SIM/SEM, vulnerability scanners, and encryption. • Reviewed proposals to significantly enhance or modify the configuration or functionality of intranets, firewalls, and servers.• Monitoring which included performing analysis of system logs to identify unauthorized use or access.• Assisted in gathering information and analyzing existing capabilities to help the team manage its service catalog.• Made recommendations to management regarding customer feedback and ways to improve services.Monitor VPNs, server logs, firewall logs, intrusion detection/prevention logs, network traffic, and other security systems for unusual or suspicious activity. Report such activity to appropriate individuals within the team.• Participated in emergency response team activities for responding to various security incidents.• Provided in-depth support for information security incidents including internal violations, hacker attacks, viruses, and system outages.

Dec 2018 - Feb 2021

Assistant Manager

Hong Kong, Hk

Risk and IT Operation• Successfully maintained security compliance within the regulator’s guidelines and achieved 100% compliance across all internal security audits for 3 years• Respond to over 300 regulator's referrals and inquiries on IT-related complaint cases over 4 years, conducted root-clause analysis, submitted investigation reports, send replies to customers• Participated in the incident response team, identified and promptly reported to the regulatory body for 16 reportable incidents like data leakage• Conducted in-depth investigations, submitted investigation reports to the regulator including remedies and improvement schedule and avoided further actions from regulators for four consecutive years of service• Performed over 500 risk assessments for banking products and services, measured the impact and likelihood of the technology-related risks, managed and controlled the risks via preventive and mitigation measures.

Sep 2013 - May 2017

Asistant Manager

Hk

Enforcement and AML division• Analyzed and accessed to IT Governance of banks following the HKMA Supervisory Policy and the ISO27000 standard.• Performed and managed 20+ on-site examinations, desktop reviews, and other off-site supervisory activities on e-banking, technology risk management (TRM), Fintech, cybersecurity and business continuity planning (BCP) of over 15 banks in Hong Kong• Drafted updates on HKMA’s guidelines on e-banking, TRM, Fintech, cybersecurity and BCP in the light of local and overseas regulatory, industry and technology developments in 2010 and 2012• Oversaw customer complaints against 10+ banks in Hong Kong in connection to information technology• Assessed Banks’ compliance via reviewing over 200 investigation reports by following the guidance from HKMA in managing technology-related risks• Instructed and monitored the bank's enhancement of internal control and operational practices and directed implementation for more than 10 banks• Partnered with banks IT steering committee and senior management to evaluate the effectiveness of enhancements

Jun 2009 - Aug 2013
3 education records

David C. education

Master'S Degree, Computer And Information Systems Security/Information Assurance

Penn State College Of Information Sciences And Technology

Master Of Science - Ms, Finance

University Of London

Postgraduate Diploma, Economics

University Of London
FAQ

Frequently asked questions about David C.

Quick answers generated from the profile data available on this page.

What company does David C. work for?

David C. works for SS&C Technologies.

What is David C.'s role at SS&C Technologies?

David C. is listed as Senior Application Security Engineer at SS&C Technologies.

What is David C.'s email address?

AeroLeads has found 1 work email signal at @scif.com for David C. at SS&C Technologies.

Where is David C. based?

David C. is based in Pleasanton, California, United States while working with SS&C Technologies.

What companies has David C. worked for?

David C. has worked for Ss&C Technologies, Savvymoney, State Compensation Insurance Fund, Hang Seng Bank, and Hong Kong Monetary Authority (Hkma).

How can I contact David C.?

You can use AeroLeads to view verified contact signals for David C. at SS&C Technologies, including work email, phone, and LinkedIn data when available.

What schools did David C. attend?

David C. holds Master'S Degree, Computer And Information Systems Security/Information Assurance from Penn State College Of Information Sciences And Technology.

What skills is David C. known for?

David C. is listed with skills including Cisa, Nikto, Computer Forensics, Information Security, Banking, Distributed Systems, Linux, and Cissp.

Find 750M verified contacts

Search by job title, company, industry, location, and seniority. Export verified B2B contact data when you need it.