Engineering Manager & Application Security Engineer
San Francisco, Ca, Us
As manager: Launched 2FA for Twitter accounts, the bug-bounty program, a rewrite of production login systems, and account anomaly detection, all while performing company-wide security reviews. Rewrote and taught our writing secure code class. Responsible for static and dynamic code analysis. Defined and executed on team and company-level roadmaps. Lots of hiring. Frequent presenter in engineering-wide and company-wide meetings (“tea time”).As engineer: Found and fixed security problems across nearly all our codebases. Developed a credential-abstraction solution that is surprisingly still in use today. Worked on XSS, CSRF, CSP, TLS, OAuth, mobile, web, backend, ops, you name it.