Senior Manager, Sofware Engineering
CurrentImplemented an automated vulnerability management process, resulting in a significant reduction in the time taken for review submissions. This comprehensive solution has streamlined our software delivery and scanning processes, enhancing overall efficiency.Established a robust personal data assessment process to ensure compliance with GDPR, GLBA, HIPAA, and PCI requirements across our products. This proactive approach ensures the protection of sensitive information and regulatory compliance.Evaluated and implemented industry-leading tools such as HCL AppScan Enterprise for Static Application Security Testing (SAST) and Aqua Security for container security. These tools have significantly bolstered our security posture and mitigated potential vulnerabilities.Lead the Global Security Engineering team, setting the direction for secure development policies and standards for software developed by ACI. This leadership role involves providing security thought leadership, consulting, and training on Secure Software Development Life Cycle (SSDLC) practices to ACI staff.Implemented application threat modeling as part of our internal compliance efforts, enabling proactive identification and mitigation of potential security risks in software applications.Collaborated with internal and external customers to address software security challenges and review customer agreements to ensure compliance with software security requirements.Conducted annual secure code training for over 1400 engineers, ensuring that our teams stay up to date with the latest industry best practices. Regular training content updates are made in response to changes in OWASP guidelines.Prepared the Security Engineering Team for strategic initiatives such as containerization, CI/CD, and DevOps, ensuring that security considerations are integrated into these key areas.