Lead Information Security Engineer, Vice President
CurrentDesign, develop and implement secure software best practices for the Enterprise Application Security Program at Wells Fargo. As part of the Secure Software Development Lifecycle (SSDLC) program, I am responsible for the security requirements program. I manage the security requirements and design tools, like SD Elements from Security Compass. I work collaboratively with application and security champions early in the SDLC to establish security requirements through modeling and research activities. I help educate application stakeholders to understand relevant security issues, including practical strategies for fully mitigating or partially compensating the associated risks I participate in defining, reviewing, and promoting information security policies, standards, guidelines, and procedures I also participate in internal process improvement initiatives. I mentor junior staff as the SME in security requirements. I have an understanding of common industry security categorization schemes, such as STRIDE and common industry risk ranking models, such as DREAD, CVSS, OWASP Risk Rating Methodology. I build and deliver training content (Brown Bags, ) to Developers, Testers and other security professionals. I identify emergent software security vulnerabilities and threats and design methods to identify those vulnerabilities and provide remediation alternatives. Consult and design threat models for the Secure SDLC process. Developed the safe coding standards for Cloud environments, Amazon AWS and Microsoft AZURE. Develop safe coding standards and guidelines for the development teams in Java, C, and Mobile development. Subject Matter Expert (SME) responsible for application security and software security best practices. Consult with development groups on the implementation of Security Development Lifecycle best practices and tools. Research, development and /or customization of software security tools and libraries.