I am a Security Executive with extensive senior leadership experience in vulnerability and container security, having worked at Amazon, Microsoft, and ServiceNow. Throughout my career, I have successfully driven significant reductions in critical vulnerabilities and ensured full compliance with FedRAMP, PCI DSS, and HIPAA standards. My expertise includes developing frameworks and pipelines that accelerate remediation and reduce risk exposure.
At ServiceNow, I currently serve as a Senior Vulnerability Response and Compliance Consultant, where I enhance security postures for commercial and federated environments, achieving high SLA compliance. I conduct risk assessments using NIST RMF and CVSS scoring and apply remediation strategies that maintain compliance and reduce exposure. I have pioneered AI-driven compliance forecasting and developed AI-focused false positive analysis pipelines to improve vulnerability accuracy.
During my tenure at Amazon, I led vulnerability, container, and attack surface security management. I developed Amazon’s first CVE assessment framework, leveraging AI and machine learning to prioritize remediation and reduce risk. I managed large-scale deployments of vulnerability management agents and streamlined scanning processes, significantly improving remediation timelines and compliance.
At Microsoft, I managed service engineering teams and implemented patching strategies that maintained high compliance SLAs. I engineered resilient monitoring infrastructures and collaborated with security teams to reduce exposure times for critical vulnerabilities. I also managed SDLC initiatives to align IT services with business objectives and reduce security incidents.
I am passionate about leveraging deep security expertise to strengthen enterprise protection and compliance outcomes. I excel in strategic planning, team leadership, and process optimization, and I am committed to driving continuous improvements in security posture and operational efficiency.
Enhanced security posture for commercial and federated environments, achieving 98% SLA compliance monthly across FedRAMP, PCI DSS standards. Conducted risk assessments using NIST RMF and CVSS scoring and applied remediation adjustments. Collaborated with system owners and CISO to deliver monthly compliance metrics. Pioneered AI-driven compliance forecasting and developed AI-focused false positive analysis pipelines. Designed and implemented a Small Language Model for proactive vulnerability identification, reducing critical risk exposure by 25%.
Led vulnerability, container, and attack surface security management. Developed Amazon’s first CVE assessment framework, cutting remediation time by 40%. Leveraged AI and ML for vulnerability prioritization, reducing risk exposure by 30%. Managed large-scale deployment of Qualys VM agents across millions of devices, resolving 90% of vulnerabilities in 3 months. Reduced OT/ICS scan durations significantly and engineered semi-automated processes to cut assessment efforts by 55%. Scaled team from 2 to 30 engineers, achieving 100% FedRAMP and PCI DSS compliance. Authored a 3-year security and tooling roadmap.
Implemented silent patching reducing forced reboots by 70%, maintaining 95% patch compliance SLA. Collaborated with Information Security to assess vulnerabilities and deploy patches. Engineered SCOM/SCCM infrastructures with failover for FedRAMP-compliant monitoring. Directed early deployments of Configuration Manager and Windows Intune in Azure. Managed SDLC for 300K+ systems ensuring anti-malware, patching, and OS deployments per OWASP best practices. Partnered with cross-functional teams to improve IT service alignment and reduce security incidents.
Jobicy
588 professionals pay to access exclusive and experimental features on Jobicy
Free
USD $0/month
For people just getting started
Plus
USD $8/month
Everything in Free, and: