Application Security Sme
CurrentRisk Management BranchCompleted Tasks: • Led the code review team tasked with performing code reviews for source code findings within HP Fortify Enterprises. • Provided complete administration support for HP Fortify (Enterprise) • Integrated scan capabilities and configurations with GitHub repositories using token authentication, triggered by CI pipelines.• Provided context and false positive support prior to development team engagement.• Developed processes to provide remediation paths with development teams, supporting a streamlined approach to remediation of findings.• Consulted with developments team on best known methods and practices for remediation of findings.• Conducted brownbag seminars on Fortify capabilities and integration within CI/CD as week as the remediation process.• Provided DAST analysis support using HP Web Inspect • Supported monthly scans of authenticated USCIS web application support Major Accomplishments:• Successfully stood up a functional code review program designed to assist development teams in moving software security practices further left within the SDLC. • Reduced USCIS source code finding technical debt (through analysis and false positive assignments) by over twenty-eight thousand and holding an average of less than one thousand findings needing initial review monthly. • Developed a Fortify dashboard within SPLUNK to provide customized visibility to types of vulnerabilities within USCIS’s code base as well as context to application security postures across the division.