Nicholas Sturm

Nicholas Sturm Email and Phone Number

Senior Software Security Engineer @ Self-employed
Seattle, WA, US
Nicholas Sturm's Location
Seattle, Washington, United States, United States
Nicholas Sturm's Contact Details

Nicholas Sturm work email

Nicholas Sturm personal email

About Nicholas Sturm

Security at ConvoyAt Convoy I was a part of a small (~4 eng) Multi-Domain Security Engineering team within the Engineering Infrastructure org. Convoy Security was the first and primary owner for any security related topic, and partnered with Engineering teams, Leadership, IT, Legal and Risk teams that formed over the years.As a Part of this role I learned and developed many Application Security and Corporate Security skills. Additionally I took part in DFIR and GRC processes, as well as a mentor to several new engineers.-------------------------------------------------Previously: working in Security Assurance for the Windows Org, focusing on Static Code Analysis. Wrote source code static analyzers and automating infrastructure to discover, analyze and file issues over a 250GB source database. Also integrating third-party systems such as Semmle and Flexera into our Engineering System.Have previously focused on developing static analysis rules to generalize common attack vectors, Centralizing data and making it highly correctable and re-usable, enabling Security developers to be more effective by providing security utility tools and enabling broad scale security rules to work within windows engineering systems.Previously worked within Microsoft in the roles of Test and Quality May 2007 - April 2017. Driven Quality and Security for various teams at Microsoft including Office, SharePoint, Xbox, and Windows. Have worked on a diverse range of products including SharePoint 2012, SharePoint 2014, Office 365, Windows Phone, PlayReady for Android and iOS, Xbox 360, Xbox One, Windows 10. Have expanded and utilized various skills to perform Pen Testing, Security Training, Build Lab, Device Lab, Automation Frameworks, Software Life Cycle planning, Sustaining Engineering.

Nicholas Sturm's Current Company Details
Self-employed

Self-Employed

View
Senior Software Security Engineer
Seattle, WA, US
Nicholas Sturm Work Experience Details
  • Self-Employed
    Senior Software Security Engineer
    Self-Employed
    Seattle, Wa, Us
  • Amazon Web Services (Aws)
    Senior Security Engineer
    Amazon Web Services (Aws) Aug 2023 - Present
    Seattle, Wa, Us
  • Convoy Inc
    Senior Security Engineer
    Convoy Inc Sep 2019 - Feb 2023
    Seattle, Wa, Us
    Security EngineeringDeveloped Secure Development Lifecycle Process– Incorporated 3rd Party Review of new SaaS integration into purchasing process including developing a Relative Risk Matrix, allowing for baselining new SaaS applications against known existing a market examples– Developed and conducted Secure Design Reviews with engineering teams. I prioritized Security Guidance to achieve product goals and while understanding and mitigating riskPentesting Lead for Internal and External tests. Discovered multiple complex issues requiring multi-team resolution and coordinationSecrets in Code– Automated Pattern Based detection of secrets in code – Developed secrets libraries and Infrastructure to assists Engineering teams– Led engineering wide effort of secret removal and drive to zeroCompany Security Education– Wrote and delivered Engineering Technical Talks on Secure Design Process, Pentesting, and Security Incidents– Developed and taught engineering Intro to Security course– Partnership with IT on developing corporate wide Annual Security Training—---------------------------------------------------Corporate Security, DFIR, GRCEnterprise GitHub Migration and Admin– Drove integration of SSO– Designed and implemented permission restrictions– Designed and deployed repository restrictions and rulesAuthentication and Authorization– Assisted the formation of an Authentication Team– Part of Team to provide Guidance and RequirementsLead the Open Source Policy team– Primary Author and Leader to develop Policies or OSS Use, Contribution, and Publishing– Performed Audit and Analysis of Uses and LicensesSecurity Incident Response–Lead multiple major security incident responses including, Log4J, CircleCi breach, and internal misuse of resources for cryptoPrimary Security Leader for Fraud Investigations– Unauthorized 3rd Party Spoofing of APIs– External Data and Web Scraping
  • Microsoft
    Security Software Engineer
    Microsoft Apr 2017 - Sep 2019
    Redmond, Washington, Us
    Working in Window and Devices Group, Platform Security & Research and Development doing Security Assurance Tooling and Automation at Scale.Responsible for design, development, deployment and integration of security tooling to enable static and dynamic analysis with engineering systems. Developed tooling to wrap Semmle snapshot creation into the Windows developer build tooling and automatically execute suites of Semmle rules. Developed and integrated tooling for processing SAIRF output, reducing multiple results into single actionable issues, and making reported issues more actionable by adding specific context source code snippets, and pipelined into to Azure Dev Ops for the Windows organizationCreated a universal Attack Surface database and automation infrastructure that allows for multiple tools to report attack surface to a centralized DB and then correlate data between different releases/builds and other data sources, using Azure CosmosDB and Azure Batch.
  • Microsoft
    Software Engineer
    Microsoft Sep 2015 - Apr 2017
    Redmond, Washington, Us
    Software Engineer in Quality for the OS Security team within the Windows and Devices Group.Worked on Enterprise Data Protection. focusing on Networking and Policy Deployment.
  • Microsoft
    Software Engineer
    Microsoft Oct 2011 - Sep 2015
    Redmond, Washington, Us
    PlayReady Media DRM for First Party Ports (Android, iOS, Windows Phone, Xbox)
  • Microsoft
    Software Development Engineer In Test
    Microsoft May 2007 - Oct 2011
    Redmond, Washington, Us
    Authentication and Security for Microsoft Office SharePoint Server, Office 365, SharePoint Online.
  • Analog Devices
    Engineering Co-Op Intern
    Analog Devices Jan 2006 - Jun 2006
    Wilmington, Ma, Us
    Engineering Co-Op 3: Wrote serial sd card drivers for DSP platformsDSP Applications EngineerAccomplishment: Designed an interface for programming external flash memory using existing IDE tools- Executed several projects involving Digital Signal Processor development board and peripherals- Developed proprietary software for an embedded system to create a GUI taking advantage of an existinggraphics package- Characterized and tested preproduction DSP silicon for worst case scenario delays- Provided pre and post sale support for issues and opportunities for existing and potential customers
  • Groove Networks
    Quality Assurance Automation Engineer
    Groove Networks Jan 2005 - Jun 2005
    Us
    Engineering Co-Op 2: Working on testing of online simultaneous collaboration platform.Groove Networks was purchased by Microsoft in March of 2005Accomplishment: Increased the product reliability through identifying and resolving errors in product- Executed mandatory mandatory automated testing on daily builds of the Groove Virtual Office Product- Collaborated directly with developers to trouble shoot and resolve bugs to improve product stability before release, resulting in increased customer satisfaction- Tested various quality aspects of the product on multiple operating systems and hardware setups- Worked under strict deadlines for releasing products and successfully completed all tasks required
  • Cognex Corporation
    Tech Support Engineer
    Cognex Corporation Jan 2004 - Jun 2004
    Natick, Ma, Us
    Engineering Co-Op I: Working as tier 1 tech support of Machine Vision SystemsHandled front line response to all customer issues, managing a significant case load- Identified, tested and resolved customer issues involving in the In-Sight® product line- Optimized product capabilities for optical recognition to meet rigorous pass/fail requirements for enterprise level customers- Set up communications using Ethernet, Serial, and Discrete digital I/O between product line and PLCs- Created sample code in C# for communication using TCP/IP in a .Net framework

Nicholas Sturm Skills

Software Development Test Automation C# Software Engineering Software Quality Assurance Test Planning Agile Methodologies Distributed Systems Visual Studio Scrum .net Software Design Performance Testing Testing C++ Debugging Test Cases Java Ios Sharepoint Android Semmle Static Analysis

Nicholas Sturm Education Details

  • Northeastern University
    Northeastern University
    Computer Engineering

Frequently Asked Questions about Nicholas Sturm

What company does Nicholas Sturm work for?

Nicholas Sturm works for Self-Employed

What is Nicholas Sturm's role at the current company?

Nicholas Sturm's current role is Senior Software Security Engineer.

What is Nicholas Sturm's email address?

Nicholas Sturm's email address is ns****@****voy.com

What schools did Nicholas Sturm attend?

Nicholas Sturm attended Northeastern University.

What are some of Nicholas Sturm's interests?

Nicholas Sturm has interest in Animal Welfare, Education, Science And Technology.

What skills is Nicholas Sturm known for?

Nicholas Sturm has skills like Software Development, Test Automation, C#, Software Engineering, Software Quality Assurance, Test Planning, Agile Methodologies, Distributed Systems, Visual Studio, Scrum, .net, Software Design.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.