Security Ownership Overview

I connect technical controls with the people and processes that keep them effective.

Product and application security

My work covers design reviews, threat modeling, code review, and assessments of web, API, and mobile applications. At Licious, I established the Product Security function as the first dedicated security engineer. Read the case study.

Secure delivery and cloud controls

I integrate security checks into developer workflows and use application context to prioritize cloud risks. This includes Semgrep and Trivy in CI/CD, AWS posture review, and attack-path prioritization.

Vulnerability operations and governance

A useful control needs an accountable owner, evidence of operation, and a remediation path. My responsibilities include bug bounty operations and ISO 27001 readiness, coordinating work across technical and business teams.

Career and contact

See the experience timeline, résumé, and public research for supporting context.

I’m interested in senior Product Security, AppSec, Cloud Security, and security engineering lead roles. Get in touch.