Summary
Overview
Work History
Education
Skills
Certification
Work Availability
Timeline
Hi, I’m

Tambra Horn CISSP CISA CEH

Senior Application Security Engineer/Architect
Tambra Horn  CISSP CISA CEH

Summary

Watchful professional offering comprehensive, hands-on experience identifying, investigating and responding to product security issues. Expertise in identifying threats and anomalies and administering metrics to quantify and qualify effectiveness of security processes and controls. Focused on helping businesses safeguard their products from hackers and cyber-criminals.

Overview

28
years of professional experience
6

Years of AppSec experience

Work History

Pay Near Me
Santa Clara, CA

Senior Application Security Engineer
09.2022 - Current

Job overview

  • Evaluate security technology, methodology, and tools to better software development life cycle
  • Improve and support application security tool services including static analysis, dynamic testing, software composition analysis tools
  • Support incident response and architecture review processes whenever application security expertise is needed
  • Manage routine penetration testing services, including both expert consulting and managed services
  • Provide manual penetration testing and standards gap analysis services to internal business and technology partners
  • Support, improve, and maintain secure development standards and application security framework projects
  • Support Vendor Management activities to ensure third party software and development meet security standards
  • Integrate threat modeling practices into product development life cycle
  • Collaborate alongside DevOps, QA, and Engineering to improve security of applications architected 100% on cloud (AWS) microservices-based environment.

HeartFlow

Application Security Architect
12.2021 - 06.2022

Job overview

  • Application Security Subject Matter Expert - Passionate about meeting the development where they are to provide guidance towards “shifting left”.
  • Conduct proof of concept for future SAST,DAST,and SCA solutions that align with software architectural changes and language coverage gaps.
  • Approve application security related design review, scan results, and remediation for every software release.
  • Interface with the Customer Success to discuss and track security feature enhancement requests from our global customers
  • Calibrate flaw severity by performing a risk assessment (asset,exposure,etc)
  • Define application security policy, best practices and standards
  • Define Security Champions curriculum - annual secure code training requirements
  • Track and present Application Security compliance related metrics to CISO and C-Suite executives

Sabre, Risk and Security 

Senior Application Security Engineer
05.2018 - 12.2021

Job overview

  • Veracode - Performed SAST and DAST scans and secure code reviews.
  • Support DevSecOps (CI/CD pipeline) integration.
  • Create Python scripts using Veracode REST API module that automate repetitive workflow processes and pull metrics that measure application policy compliance.
  • Burp Suite - Performed manual web application penetration testing focusing on OWASP Top 10.
  • Performed Risk Assessment of third party software
  • Successfully drove CISO approval of the Application Security Policy and Standard.
  • Established Secure Code Champions training curriculum

Jack Henry and Associates

Application Security Engineer, Advanced
11.2016 - 01.2018

Job overview

  • Web Application Security
  • F5 LTM Administration - Configure, maintain, and troubleshoot VLAN creation, virtual server creation, pool creation (load balancer config) via GUI or TMSH (Proprietary F5 CLI) scripting. Execute corporate migrations and disaster recovery exercises.
    Security Services Operational Administration- Identify and escalate any anomalies found appropriately. (McAfee ePO, ForcePoint,IronPort)
  • Qualys Administrator - Create and analyze vulnerability scans and reports on corporate network.
  • ForcePoint (WebSense) - Perform, troubleshoot, and maintain Policy Exceptions, Categorical filtering, URL block and unblock requests. Perform web appliance swaps.

Education

Prairie View A&M University 
Prairie View, TX

from Computer Science
09.1993 - 05.1995

University Overview

• B. SC. Computer Science, 1995, Prairie View A&M University

Skills

SAST, DAST

undefined

Certification

CISSP #47289    *    CISA #1078941

Availability
See my work availability
Not Available
Available
monday
tuesday
wednesday
thursday
friday
saturday
sunday
morning
afternoon
evening
swipe to browse

Timeline

Senior Application Security Engineer

Pay Near Me
09.2022 - Current

Application Security Architect

HeartFlow
12.2021 - 06.2022

Senior Application Security Engineer

Sabre, Risk and Security 
05.2018 - 12.2021

Application Security Engineer, Advanced

Jack Henry and Associates
11.2016 - 01.2018

Prairie View A&M University 

from Computer Science
09.1993 - 05.1995
Tambra Horn CISSP CISA CEHSenior Application Security Engineer/Architect