Michael Maass

Michael Maass Email and Phone Number

Principal Cybersecurity Systems Engineer @ Torc Robotics
Pittsburgh, PA, US
Michael Maass's Location
Pittsburgh, Pennsylvania, United States, United States
Michael Maass's Contact Details

Michael Maass personal email

n/a
About Michael Maass

Between hobby projects and professional experience, I have more than 20 years of cybersecurity experience. I've spent the last 16 years working to build secure companies and products and top-tier cybersecurity teams. I have a wide range of experience covering from software development in x86 assembly, C/C++, Java, and other languages to managing people and communicating with regulators and other critical stakeholders external to my employers. My passion is for developing secure, safety critical cyber-physical systems using cutting-edge practices to achieve acceptable liability and pass regulatory muster.

Michael Maass's Current Company Details
Torc Robotics

Torc Robotics

View
Principal Cybersecurity Systems Engineer
Pittsburgh, PA, US
Michael Maass Work Experience Details
  • Torc Robotics
    Principal Cybersecurity Systems Engineer
    Torc Robotics
    Pittsburgh, Pa, Us
  • Torc Robotics
    Principal Cybersecurity Systems Engineer
    Torc Robotics Jul 2024 - Present
    Blacksburg, Va, Us
  • Motional
    Director Of Cybersecurity
    Motional Apr 2022 - May 2024
    Boston, Massachusetts, Us
    As Motional's Director of Cybersecurity, I continued my leadership of ProdSec and took on all other cybersecurity functions. This taught me that while I love all cybersecurity topics, I tend to prefer those related to building products.Key Successes:- Managed public release of Motional's Security Development Lifecycle (SDL) / Cybersecurity Management System (CSMS), called AVCDL, including partial training content. To my knowledge, this is the first SDL / CSMS purpose-built for developing secure safety critical systems publicly released in full- Managed external assessments of AVCDL to ISO/SAE 21434 and UN R155, resulting in two confirmation letters from TÜV SÜD - Primary contributor to the successful case to create Motional's Compliance function and reinvorgate the Quality Management function. Led effort that hired a Quality Director- Directed the implementation of secure boot, secure update (A.K.A. secure flashing), device authentication (including UDS 0x29 PKI-based authentication), and secure communication (including TLS, Autosar SecOC, and Autosar Black Channel) in cameras, lidars, high performance compute, drive-by-wire, remote vehicle assistance, and other ECUs. This included making risk-based decisions about bugs and vulnerabilities or when faced with implementation delays- Directed implementation of AVCDL processes including static and dynamic analysis, penetration testing, risk analysis, and more, all contributing to a product safety case- Doubled IT Security headcount and filled the roles with top-tier hires. Retooled how this team performed program and project management. This took the team from treading water to sustainably and effectively defending the business- Initiated and staffed an ISO 27001 compliance program; completed a first successful audit in Spring 2024- When my time at Motional ended, I was working cross-functionally to implement requirements processes, a TARA process, application lifecycle management, and much more
  • Motional
    Cybersecurity Lead, Principal Engineer
    Motional Mar 2020 - Apr 2022
    Boston, Massachusetts, Us
    I led cybersecurity negotiations between Aptiv's Autonomous Mobility (AM) division and Hyundai. This was part of a larger effort that closed a multi-billion dollar deal to form Motional. I managed all Product Cybersecurity functions in this joint venture as I previously did in Aptiv's AM division.Key Successes:- Founded cybersecurity team now serving all aspects of product security across the company- Hired and managed cybersecurity experts working across two US states and three countries- Managed creation of security development lifecycle complying with ISO 21434- Managed creation and spearheaded communication of product development lifecycle to unify systems (ISO 15288), software (ISO 12207), safety (ISO 26262), and security (ISO 21434) lifecycles- Co-inventor of seven cybersecurity technologies and processes that turned into patents- Primary author of the cybersecurity content in "Safety First for Automated Driving" -- now ISO/TR 4804:2020- Primary author of the cybersecurity content in Motional's first Voluntary Safety Self-Assessment (VSSA)- Used threat modeling to formulate the "Big Four" technologies disclosed in our VSSA -- used Big Four to consistently communicate top priorities to senior leadership and to coordinate key projects across a dozen suppliers- Implemented preliminary security monitoring and incident response process- Worked across the enterprise to gain support for a successful transition from C++11 to C++14- Gained corporate membership to Auto-ISACRepresentative Responsibilities:- Lead efforts to comply with cybersecurity standards and regulations within the automotive industry- Formulate and execute cybersecurity strategy- Manage cybersecurity implementation- Inform senior leadership of cybersecurity risks and deliver recommendations- Coordinate cybersecurity efforts in collaboration with Aptiv, HMC, and the supply chain
  • Aptiv
    Autonomous Vehicle Cyber Security Lead
    Aptiv Nov 2017 - Mar 2020
    Dublin, Ie
    I led a team of talented engineers and specialists responsible for ensuring that self-driving vehicles and supporting infrastructure built by Aptiv's Autonomous Mobility division are difficult for hackers to successfully attack. We collaborated with teams across the division and outside stakeholders at every development stage from concept definition to product verification.
  • Bezirk - A Bosch Start-Up
    Lead, Usable Iot Security
    Bezirk - A Bosch Start-Up Apr 2016 - Nov 2017
    Design, analyze, and implement privacy-protecting middleware and personalization-on-the-edge technologies. Lead software engineering efforts across multinational Agile team emphasizing privacy, security, and quality.At Bezirk I have been able to test myself as a leader within a diverse team of impressive people. Every day has brought me new opportunities to mentor junior developers, design software systems, lead software engineering efforts, pick technologies to build on, contribute to business strategy, and so much more.Selected Responsibilities:- Lead software engineering efforts to develop a retail recommender system that runs on consumer phones- Architect deployable retail personalization solution to realize go-to-market strategy- Design and evangelize Security Development Lifecyle and software quality processes- Train development team spanning two countries and several cultures in secure software development and modern software engineering practices- Architect and analyze innovative security and privacy mechanisms
  • Carnegie Mellon University
    Phd Candidate
    Carnegie Mellon University Aug 2011 - Mar 2016
    Pittsburgh, Pa, Us
    My research interests broadly fall within the domain of software security. In particular, I specialize in the use of sandboxes to encapsulate computations that may be vulnerable or malicious to contain unwanted behaviors. I started by designing a sandboxing mechanism for rich and extremely complicated file formats (e.g. PDF, DOC, PPT, etc.), but later turned my attention to enhancing the security and usability of existing sandboxes. In particular, my thesis project focused on eliminating unnecessary and vulnerability ridden functionality in the Java sandbox and tooling to overcome necessary complexity that is currently hampering sandbox deployment. The final project in my thesis uses program analysis and rewriting on Java bytecode to automate fine-grained application of the Java sandbox.I was a founding member of Carnegie Mellon's NSA Science of Security Lablet. I also had the privilege of working on a special project to advise the US government on the state of contractor-produced software developed for government agencies. This led to a series of a recommendations for altering contractor/government relationships to improve results.Outside of research, I found many opportunities at Carnegie Mellon to:- Give invited guest lectures on various security topics in undergraduate courses- Speak to executives at various companies about my research- Work with potential collaborators to define project goals, execution strategies, and formal statements of work- Mentor more junior PhD students
  • Boeing
    Security Engineer
    Boeing May 2008 - Mar 2016
    Arlington, Va, Us
    Design and implement secure software systems and consult on projects requiring security expertise.In my time at Boeing I acted as a consultant on more than twenty high assurance projects that needed secure design and coding expertise. I also acted in a consulting role to fix more than 100 vulnerabilities. The vulnerabilites I have fixed are diverse: common web application issues (OWASP Top 10), mistaken use of cryptography libraries, memory corruption and threading issues, missed mitigations in hardware systems, etc.Dedicated Projects:- Design, implement, and support two-factor authentication mechanisms- Design and support Boeing's Security Development Lifecycle and supporting tools- Modernize and simplify application threat modeling processes- CMS for Board of Directors- Define, manage, and drive cybersecurity R&D collaborations with universities- Reusable ModSecurity VM deployment for temporary vulnerability mitigation- Design and implement identity management solutions Special Projects:- Design of Boeing's formal Application Security job role- Define Boeing's IT university relations strategy- Application Security representative on CTO's Advanced Persistent Threat Panel- Application Security representative on enterprise-wide Insider Threat Mitigation project

Michael Maass Skills

Information Security Engineering Computer Security Application Security Web Application Security Security System Design Vulnerability Assessment Vulnerability Research C++ C Java Python X86 Assembly Software Design Software Development

Michael Maass Education Details

  • Carnegie Mellon University
    Carnegie Mellon University
    Computer Software Engineering
  • Carnegie Mellon University
    Carnegie Mellon University
    Software Engineering
  • Washington State University
    Washington State University
    Electrical Engineering
  • University Of Portland
    University Of Portland
    Electrical Engineering

Frequently Asked Questions about Michael Maass

What company does Michael Maass work for?

Michael Maass works for Torc Robotics

What is Michael Maass's role at the current company?

Michael Maass's current role is Principal Cybersecurity Systems Engineer.

What is Michael Maass's email address?

Michael Maass's email address is mi****@****ing.com

What schools did Michael Maass attend?

Michael Maass attended Carnegie Mellon University, Carnegie Mellon University, Washington State University, University Of Portland.

What skills is Michael Maass known for?

Michael Maass has skills like Information Security Engineering, Computer Security, Application Security, Web Application Security, Security System Design, Vulnerability Assessment, Vulnerability Research, C++, C, Java, Python, X86 Assembly.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.