Matthew Westfall

Matthew Westfall Email and Phone Number

Senior Security Engineer at Salesforce @ Salesforce
San Francisco, CA
Matthew Westfall's Location
Elizabethtown, Pennsylvania, United States, United States
Matthew Westfall's Contact Details
About Matthew Westfall

Matthew Westfall is a Senior Security Engineer at Salesforce at Salesforce. He possess expertise in java, information security, network security, javascript, penetration testing and 29 more skills.

Matthew Westfall's Current Company Details
Salesforce

Salesforce

View
Senior Security Engineer at Salesforce
San Francisco, CA
Website:
salesforce.com
Employees:
1
Matthew Westfall Work Experience Details
  • Salesforce
    Senior Security Engineer
    Salesforce May 2022 - Present
    San Francisco, California, Us
    - Conducting secure architecture review of full stack cloud applications- Authoring risk assessments and remediation guidance for developers and stakeholders- Performing manual penetration testing and source code review for a variety of technologies- Developing security tooling for the detection and prevention of security threats- Performing independent research on emerging threats and vulnerabilities
  • Nvisium
    Principal Application Security Consultant
    Nvisium Jun 2020 - May 2022
    Falls Church, Va, Us
    - Led security assessments for web applications, networks, and cloud-hosted assets- Defined and developed core capabilities in application and cloud security service offerings- Authored and reviewed technical documentation including proposals, reports, and deliverables- Created remediation guidance and engineering solutions for product teams and senior leadership- Performed independent research on topics relevant to cloud security and the threat landscape
  • Mindpoint Group, Llc
    Security Team Lead
    Mindpoint Group, Llc May 2016 - Jun 2020
    Mclean, Virginia, Us
    Federal Client (June 2016 – June 2020)Provided security services to a government agency migrating to a cloud environment powered by Amazon Web Services (AWS): - Conducted full-scoped penetration testing of cloud-hosted applications - Provided guidance on network architecture and application security - Performed OSINT research to provide actionable threat intelligence - Integrated security services into automated development pipelinesCreated and released “CloudFrunt” – an open-source AWS CloudFront exploitation tool: - Observed anomalous behavior in customer AWS CloudFront deployments - Performed private research into exploitable issues in core CloudFront functionality - Created “CloudFrunt” tool to automate the process of discovering and hijacking domains - Squatted roughly 2,000 domains over a five-day period, which were turned over to AWS Security - Nine vulnerable federal domains were reported to US-CERT at NCCIC - Research covered by Bleeping Computer, Threatpost: disloops.com/cloudfront-hijackingPrivate Client, Financial (May 2016 – June 2016)Provided security services to a super-regional financial institution in support of an Enterprise Architecture (EA) effort.
  • Ensco, Inc.
    Software And Security Engineer
    Ensco, Inc. May 2015 - May 2016
    Vienna, Virginia, Us
    - Provided secure research and network capabilities to full-spectrum cyber operations personnel- Participated in an Agile software development lifecycle (SDLC) in a laboratory setting- Created mission-critical web applications for federal customers using RESTful API, Java, and C#
  • Mindpoint Group, Llc
    Security Consultant
    Mindpoint Group, Llc Apr 2013 - Apr 2015
    Mclean, Virginia, Us
    Federal Client (Jan 2014 – April 2015)Provided security services to a government agency migrating to a cloud environment powered by Amazon Web Services (AWS). Acted as the lead security contact for applications being deployed or updated. Responsibilities included: - Conducting targeted penetration testing of network and web applications - Performing static code reviews in a variety of languages - Creating reports to describe existing vulnerabilities and steps required for remediation - Responding to emerging threats that affect the security of hosted applications - Performed platform hardening, event monitoring, and compliance tasks as requiredFederal Client (Feb 2014 – Apr 2014)Performed an assessment of a sensitive production network in support of a legislative government agency: - Reviewed existing network inventory to define an acceptable network architecture - Enumerated active devices using a variety of network mapping tools - Performed physical verification of devices, cabling, and air gaps - Conducted vulnerability scans of network hosts using a proprietary security platform - Verified tool-driven results using manual testing where necessary - Documented network discrepancies and created remediation guidancePrivate Client, Financial (May 2013 – Dec 2013)Authored an original Application Security policy for a super-regional financial institution: - Created a charter document to describe best practices in Application Security - Performed a gap analysis of the development process and developer proficiency - Identified engagement points for new security activities - Created a developer training plan and a solution for delivering security requirements - Established attack surface analysis and threat modeling as part of application design - Succeeded in creating new roles for security experts on development teams
  • Caci International Inc
    Systems Programmer
    Caci International Inc Feb 2007 - Apr 2013
    Reston, Virginia, Us
    Participated in the full Software Development Life Cycle (SDLC) of a web interface for personnel stationed at Eastern Naval Warfare Centers – the Naval Surface Warfare Communicator: - Gathered requirements to create deliverable design documents - Deployed and maintained an Apache Tomcat web server - Implemented a compliance-based architecture using AJAX, Java, JavaScript, Perl, and PHP - Constructed data repositories within an Oracle relational database using Oracle SQL Developer - Provided continuous support and enacted revisions based on changing customer needs - Currently serving the occupational needs of 4,000+ military and contractor personnel dailyActed as Lead Developer on the following projects: - Created an Emergency Muster system for Naval Sea Systems Command (NAVSEA) Dahlgren - Created an automated system for identifying inactive phone lines and circuits

Matthew Westfall Skills

Java Information Security Network Security Javascript Penetration Testing Jquery Php Sql Solaris Threat Intelligence Incident Response Sdlc Malware Analysis Linux Network Forensics Reverse Engineering Application Security Vulnerability Research Computer Forensics Static Analysis Unix Perl Python Network Administration Burp Suite Metasploit Nmap Kali Linux Snort Nessus Wireshark Vmware Ubuntu Biometrics

Matthew Westfall Education Details

  • University Of Mary Washington
    University Of Mary Washington
    Computer Science
  • United States Naval Academy
    United States Naval Academy

Frequently Asked Questions about Matthew Westfall

What company does Matthew Westfall work for?

Matthew Westfall works for Salesforce

What is Matthew Westfall's role at the current company?

Matthew Westfall's current role is Senior Security Engineer at Salesforce.

What is Matthew Westfall's email address?

Matthew Westfall's email address is pm****@****ail.com

What schools did Matthew Westfall attend?

Matthew Westfall attended University Of Mary Washington, United States Naval Academy.

What skills is Matthew Westfall known for?

Matthew Westfall has skills like Java, Information Security, Network Security, Javascript, Penetration Testing, Jquery, Php, Sql, Solaris, Threat Intelligence, Incident Response, Sdlc.

Who are Matthew Westfall's colleagues?

Matthew Westfall's colleagues are Stijn Dejaeger, Rajat Sharma, 伊藤匠海, Liam Harrington, Justin Janczewski, Nakintu Sharon, Spencer Mott.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.