Summary
Overview
Work History
Education
Skills
Awards
Timeline
Generic
Akira Brand

Akira Brand

Denver,CO

Summary

Application Security Architect with proven experience building mission-driven security programs that protect vulnerable populations and sensitive data. Expert in embedding security throughout the SDLC, establishing Security Architecture Review processes, and partnering with cross-functional teams to assess and mitigate application-layer risks. Combines hands-on technical leadership with the ability to translate complex security issues into business risk language, ensuring security enables rather than blocks organizational missions.

Overview

3
3
years of professional experience

Work History

AVP, Application Security

Pra Group Inc
08.2024 - 10.2025


Application Security Program Leadership

Led comprehensive application security program serving financial platforms handling sensitive consumer data, defining SDLC security strategy and establishing continuous improvement processes across development teams

Owned Security Architecture Review (SAR) process including intake, risk evaluation, documentation, and stakeholder engagement for new applications and integrations

Performed threat modeling for high-risk workflows involving financial systems and sensitive consumer data, identifying and mitigating application-layer vulnerabilities before deployment


Secure Development & Tooling

Deployed and maintained AppSec tooling including SAST, DAST, and SCA platforms, aligning tool selection with developer workflows and organizational risk profile

Established vulnerability remediation framework with clear SLAs, overseeing application-layer vulnerability triage, analysis, and escalation from internal testing and external penetration testing

Created developer security education program achieving 75% regular attendance, embedding secure coding practices and security awareness throughout engineering organization


Cross-Functional Security Partnership

Partnered with platform owners and engineering teams to validate application-level security controls including authentication, authorization, audit logging, and session handling

Assessed cloud applications, workflow automations, and internal tools for security risks, collaborating with stakeholders to implement appropriate controls

Delivered regular security updates to board committees, translating technical vulnerabilities into business risk context


Program Maturity & Governance

Increased organizational security maturity 163% (OWASP SAMM: 0.3 → 0.79) through systematic assessment and improvement of security practices across all SDLC phases

Developed security policies and standards through stakeholder collaboration, ensuring practical adoption across development, operations, and IT teams

Managed application security engineering team while coordinating penetration testing operations and vendor security assessments

Founding Application Security Engineer

Resilia
01.2023 - 01.2024


SDLC Security Integration

Built application security program from ground up for late-stage startup, establishing secure development practices integrated throughout software development lifecycle

Increased CIS Security Control score from 20 to 60 within one year by implementing automated security gates, threat modeling processes, and vulnerability management workflows

Designed secure coding training program achieving 100% developer completion, reducing vulnerability discovery and remediation time while building security champions across product teams


Security Architecture & Risk Assessment

Conducted threat modeling sessions for new features and integrations, identifying data flow risks and defining secure design patterns for authentication, API authorization, and secrets management

Standardized AppSec audit process across product teams, ensuring consistent vulnerability discovery, risk evaluation, and remediation tracking

Partnered directly with development pods to assess application design, evaluate third-party integrations, and implement security controls appropriate to risk level

Education

Bachelor of Music -

University of Denver
Denver, CO
05-2010

Skills

    Application Security Architecture: Secure SDLC Design Security Architecture Review (SAR) Threat Modeling OAuth/OIDC Implementation API Security Secrets Management Session Handling Data Flow Protection

    AppSec Tooling & Testing: SAST DAST SCA Secrets Detection API Security Tools Vulnerability Management Penetration Testing Coordination Security Testing Automation CI/CD Security Gates

    Security Frameworks & Standards: OWASP SAMM CIS Security Controls OWASP Top 10 Secure Coding Practices Security Policy Development Risk Assessment Frameworks

    Collaboration & Communication: Developer Partnership Cross-Functional Stakeholder Management Technical Risk Translation Board-Level Reporting Security Champion Programs Security Education at Scale

Awards

Portal26 Champions in Security | Champion in Education | Spring 2025

Timeline

AVP, Application Security

Pra Group Inc
08.2024 - 10.2025

Founding Application Security Engineer

Resilia
01.2023 - 01.2024

Bachelor of Music -

University of Denver
Akira Brand