I am a Senior Security Engineer with extensive experience in application and cloud security, with a strong focus on AWS security, vulnerability management, and compliance frameworks such as SOC 2 and HIPAA.
I have a proven track record of implementing security controls, conducting threat modeling, and managing security incident response across applications and infrastructure. I enjoy building secure, scalable systems that support business growth and product velocity.
In my recent roles, I have owned SOC 2 certification readiness, strengthened AWS security posture through IAM management and encryption, and partnered closely with engineering teams to prevent vulnerabilities. I also work across vendors and internal stakeholders to implement IAM controls and regulatory requirements.
My background includes risk and compliance analysis, GRC program management, and web application penetration testing. I have performed security audits, delivered remediation guidance, and used tools like Burp Suite to identify vulnerabilities aligned with OWASP Top 10.
I also bring experience in technical support with a security and identity focus, where I helped resolve security incidents while balancing operational needs and compliance requirements.
Alongside my security expertise, I have hands-on development experience with full-stack technologies and AI-assisted workflows. I use this combination to improve engineering efficiency, support secure application delivery, and translate technical risks into business-impact decisions.
Owned and led SOC 2 certification readiness, implemented secure software development aligned with compliance standards, strengthened AWS security posture through IAM management, security groups, and encryption, conducted vulnerability management and security incident response, designed and enforced security controls with engineering teams, partnered with vendors and internal stakeholders on IAM controls and regulatory requirements, and utilized AI-assisted development workflows to improve engineering efficiency and secure application delivery.
Conducted risk assessments and security audits, provided actionable remediation strategies aligned with NIST frameworks, delivered reports identifying security gaps and operational risks, and managed cross-functional communication and project timelines for compliance assessments.
Performed penetration testing using Burp Suite, identified vulnerabilities in line with OWASP Top 10, and collaborated with engineering teams to strengthen application security controls and secure coding practices.
Supported identity verification processes, resolved security incidents while ensuring compliance, and provided technical support balancing security and operational requirements.
Jobicy
617 professionals pay to access exclusive and experimental features on Jobicy
Free
USD $0/month
For people just getting started
Plus
USD $8/month
Everything in Free, and: