Senior Product Security Engineer
San Francisco, Ca, Us
Led an effort to virtually eliminate account takeovers while improving general account security. This includes requiring email-based challenges from questionable sign ins, improved account audit logging and notifications of significant events, banning the use of passwords found in data breaches, removing password support from the API/git, and many smaller efforts in support of this drive. Worked with the incident response teams on many investigations as an SME to explain data but also to be on the lookout for opportunities to apply extra mitigations based on any business logic vulnerabilities.Streamlined the bug bounty with process. Migrated to the HackerOne platform, built a ruby API client, and integrated with our processes and chatops systems. Reduced time to response, time to pay, increased general quality, and provided more comprehensive and accurate data on the program.Retrofitted the primary rails application with a security header library that allowed us to provide incredibly precise and dynamic content security policies allowing engineers to fully control CSP using a simple to understand API which triggers automation for review.Improved our ruby static analysis automation tooling to be more testable, accurate, and comprehensive. This includes writing custom brakeman rules along with low-hanging regular expressions. The automation is still in use and has spread to cover nearly all of our applications instead of the primary monolith.Moved the team towards more formalized practices using project boards, stand ups, and more. I led the effort on the team to move closer towards the prescribed "how we work" framework with intention but not immediate absolutism.