Svp Security Engineering
CurrentCloud security controls Software Development Life Cycle (SDLC).At Citi I have refactored the SDLC of our cloud security controls. I work with threat modeling, vulnerability assessment, IAM, logging, and security operations teams to ensure our infrastructure and application workloads in the cloud are secure. Day to day responsibilities involve pair programming, code reviews, project management, writing software and documentation. I am promoting Authentication, Authorization, and Attestation/Accountability in the CISO organization. Month to month I meet with various teams to propose changes, collect feedback, and ensure we are working towards a common understanding of risk reduction across the organization.- Reduce cycle time of preventative, detective, and auto-remedial controls by designing and implementing new architectures and application logic- Reduce operational cost of log processing by 90% through software and architecture changes- Recommend new software for version control and remote development to senior leadership resulting in approvals and implementation- Audit developer workflow and help secure developer environments- Work across teams to vet new ideas and create new workflows in a highly regulated environment- Produce documentation espousing security ideology and meeting with stakeholders to come to consensus - Spoke at AWS Re:invent 2021 live. Prerecorded video available https://www.youtube.com/watch?v=pLtbNPiuK0E