Michael White

Michael White Email and Phone Number

Security Engineer at Amazon @ Amazon
Michael White's Location
Boston, Massachusetts, United States, United States
About Michael White

Accomplished information security and privacy professional with 15 years of experience and a broad range and depth of knowledge across product security, information privacy, infrastructure security, and regulatory compliance. Diverse experiences including advising Fortune 500 companies, helping to build a new security org at a small SaaS company, and growing the product security function at a large SaaS company experiencing fast-paced growth through acquisition. Expertise in secure development practices and tooling, threat modeling and design reviews, and application security assessments. In-depth experience in information privacy practices and guidance, application and system security monitoring, vulnerability management, and incident response and response preparedness.

Michael White's Current Company Details
Amazon

Amazon

View
Security Engineer at Amazon
Michael White Work Experience Details
  • Amazon
    Security Engineer
    Amazon May 2022 - Present
    Seattle, Wa, Us
  • Logmein
    Staff Security Engineer
    Logmein Jul 2016 - Apr 2022
    Boston, Massachusetts, Us
    LogMeIn has a portfolio of more than 10 products across the Identity, Communications & Collaboration, and Remote Solutions markets.I own the relationship between our core Information Security team and the Identity business unit. My focus is on helping our product engineering teams develop secure products.• Partnering with Product and Engineering leaders to identify and prioritize security objectives and support engineering teams to achieve those objectives.• Designing and managing a security development lifecycle to serve all of LogMeIn's 10+ distinct products. The SDL emphasizes threat modeling and secure design reviews.• Maintaining LogMeIn's Security Champion program, satellite groups within each engineering team made up of developers that are enthusiastic about security and privacy.• Driving Information Privacy initiatives and maturing information privacy practices across the organization.• Evaluating and implementing security tooling and helping to integrating scanning tools into CI pipelines• Supporting the Sales organization by joining conversations with prospects to help answer questions about product security architecture and SDL practices• Engaging with third party firms to provide independent assessments of our products, including BSIMM assessments of our software security practices and focused technical security assessments of new and strategic product features.
  • Constant Contact
    Sr. Application Security Engineer Ii
    Constant Contact May 2014 - Jul 2016
    Waltham, Ma, Us
    • Designed a new Product Security function, embedding security with developer teams and focusing on secure development lifecycle and application security.• Created a Security Advocate program, scaling security throughout the Engineering organization via a team of representative developers and quality engineers. • Coordinated implementation of static code analysis testing. • Created security training program for developers, designing a curriculum using online learning courses and selected readings.
  • Constant Contact
    Sr. Security Engineer
    Constant Contact Mar 2012 - May 2014
    Waltham, Ma, Us
    • Conducted application design reviews, working closely with engineering teams to identify security risks and suggest appropriate solutions/countermeasures. • Performed application security assessments, testing web applications for security vulnerabilities both manually and with automated scanners. • Led response to security incidents of all types and severity. Responsible for identifying root cause and coordinating with engineering and operations teams immediate and long term response. • Designed and developed dashboards and alerts for security monitoring. Responsible for analysis of dashboards and alerts and triaging/investigating any issues.• Implemented enterprise GRC tooling to further automate common compliance activities.
  • Constant Contact
    Security Engineer
    Constant Contact Nov 2009 - Mar 2012
    Waltham, Ma, Us
    • Initially a two person team, helped build the Operations Security function. Led implementation of several security and monitoring tools and was responsible for administering, troubleshooting and analysis of several others. Including VPN, IPS, Two Factor Auth, Key Management, Web Application Firewall, File Integrity Monitoring, Network and Application scanners, Log Management and GRC tools.• Created and led compliance programs for PCI DSS and SOX ITGC. Prepared the organization the organization for its first onsite PCI audit, leading gap assessment and remediation efforts. Formalized SOX ITGC compliance activities within the Operations organization, automating and streamlining processes where possible. Also led compliance efforts for EU Safe Harbor and MA 201 CMR 17. • Designed and implemented authentication solution for internal service APIs as our applications moved from a monolithic architecture to a service oriented architecture.
  • Pricewaterhousecoopers
    Senior Associate
    Pricewaterhousecoopers Aug 2006 - Nov 2009
    Gb
    • Performed a web application security assessments. Responsible for manual testing and automated security scans of applications. • Developed an information security risk assessment framework for a financial services client. The framework was created from relevant internal and industry standards and allowed the client to perform assessments more efficiently based on a single comprehensive control set. • Led national Windows Security Core Team, responsible for leading a team of over a dozen colleagues in offices throughout the country in creating and updating PwC’s Windows security standards.• Performed a gap analysis based on system access control guidelines of all payment systems for a large financial services client, identifying critical compliance gaps allowing unauthorized access. • Led successful implementations of data center configuration and compliance software, BladeLogic, for Fortune 500 companies in the Financial Services, IT Services and Defense industries. Responsible for system architecture and implementation. Resulted in centralized server management process and a reduction in man hours needed to maintain and provision servers. • Responded to a major data breach at a financial services client, performing a risk assessment of the information technology program, reviewing and updating the server monitoring process, and assisting with remediation efforts to meet PCI compliance.• Performed a risk assessment of all in scope products and developed a program office to help a Fortune 100 retail bank meet Identity Theft Red Flags regulation requirements.• Developer for a release of PwC’s FAST Audit web application, an online and centralized resource of information related to the funds that PwC audits.

Michael White Skills

Information Security Security Pci Dss Cissp Application Security Computer Security Linux Network Security Web Applications Saas Payment Card Industry Data Security Standard Sarbanes Oxley Act Cloud Computing Enterprise Software Information Security Management Data Center Penetration Testing Networking Information Technology Standards Compliance Sox

Michael White Education Details

  • Rochester Institute Of Technology
    Rochester Institute Of Technology
    Computer Science

Frequently Asked Questions about Michael White

What company does Michael White work for?

Michael White works for Amazon

What is Michael White's role at the current company?

Michael White's current role is Security Engineer at Amazon.

What is Michael White's email address?

Michael White's email address is mw****@****ein.com

What is Michael White's direct phone number?

Michael White's direct phone number is +178147*****

What schools did Michael White attend?

Michael White attended Rochester Institute Of Technology.

What skills is Michael White known for?

Michael White has skills like Information Security, Security, Pci Dss, Cissp, Application Security, Computer Security, Linux, Network Security, Web Applications, Saas, Payment Card Industry Data Security Standard, Sarbanes Oxley Act.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.