Software Security Group Director
Build and enhance the Secure Development Life-Cycle (SDLC), define application security technologies, and develop practices to secure Cadence applications. Responsible for application security architecture, risk assessment, and vulnerability management for diverse technologies and platforms. Perform assessments on Cadence applications in cloud, on-premise chambers, and co-location data centers for continuous security assessment processes, architecture review and penetration testing.Security Development Operations tools and technologies:• Open Source Security (OSS) - Software Composition Analysis (SCA) • Static Application Security Testing (SAST) • Dynamic Application Security Testing (DAST) • Runtime Application Self Protection (RASP) - Real Time Monitoring detection and prevention• Security Architecture Review - Threat Modeling• AWS and Azure WAF Configuration and whitelisting• DDOS configuration and operation• Manual Penetration Testing • Penetration testing with 3rd party vendors• Host level vulnerability Scanning • Web application security training course development and deliverySource Code Protection:• Github Enterprise deployment and consolidation world wide.• Artifactory and build component segmentation• SCA, SAST, DAST, and RASP Implementation Integration