Chief Application Security Architect charged with maturing & restructuring Application Security (AppSec) processes into a formal program. Augmented previous AppSec process that was based exclusively on automated security scans. Created new AppSec practice areas that included: Threat Modeling, Risk-Based Security Test Plan, Security Requirements (i.e. OWASP ASVS Controls Selection), Security Metrics Development. Inserted these new practice areas early in the SDLC. Created the following artifacts to support Application Security Verification Standard (ASVS) Level 1 for Internet facing applications: Threat Assessment, Software Attack Surface, Data Flow Diagram, Potential Application Attacker Profile (derived from Akamai Attack Pattern Logs), ASVS Playbook, ASVS Scorecard, and ASVS Control Categories. Developed control gates for using Webinpsect, AppScan, & Burp in code review process.