

Dynamic Product Security Specialist with over 23 years of comprehensive experience in Information Security, spanning a broad spectrum of roles from penetration testing and ethical hacking to developing and managing full-scale application and product security programs.
Recognized as an Atlanta information security community leader, I've dedicated over 12 years to serving on the board of directors for the Metro-Atlanta ISSA chapter, fostering professional growth and networking within the industry. Expertise lies in strategically implementing security practices tailored to product development environments, ensuring seamless security integration from the initial design phase to product deployment.
Directed Specialized Application Security consultations for diverse clients, providing expert guidance with a strong focus on embedding security into the product development lifecycle.
Developed and implemented Pagoda's first Application Security Program.
Spearheaded the integration of advanced security measures into Zippyar's products, establishing a fortified application environment resistant to emerging threats.
Developed and implemented FalconX's first Application Security Program.
Developed and implemented Bakkt's first Application Security Program.
Designed and implemented Application Security Programs for clients.
Initiated the organization's first application security program, securing over 750 web applications and ensuring compliance with PCI, FISMA, and HyTrust in the AWS environment, bolstering the security of cloud-based products.
Led various security projects and managed the risk validation team at Aarons, focusing on identifying and mitigating risks to safeguard product integrity and customer trust.
I worked with many security teams focusing on:
Presentations:
Security Organizations:
Application Security Program Justification and Beginning
• The need for an application security program is discussed among executive leadership. Requirements that justify the need for the program are discussed. These requirements may be any of the following or more:
o Compliane