Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic

Ryan Palmisano

Dripping Springs, TX 78704

Summary

Professional Summary

Experienced Cybersecurity Leader and Senior Security Engineer with a proven track record of developing and implementing robust security solutions to protect organizations from cyber threats. Skilled in leading cross-functional teams, conducting risk assessments, and designing secure network infrastructures. Strong expertise in implementing and managing security tools, incident response, and compliance frameworks. Outstanding communication skills and a strategic mindset to effectively mitigate vulnerabilities and safeguard critical data assets. Ready to leverage extensive experience to enhance cybersecurity posture and drive organizational success.

Overview

12
12
years of professional experience
1
1
Certificate

Work History

Senior Cloud Infrastructure Engineer

Swish Analytics
07.2024 - Current

Penetration tested their entire ego-system which took roughly a month and half. I used the latest OSINT, OWASP, and Offensive Security based tooling to find and catalogue all digital assets we should be concerned with and made a report using latest practices.


As DevOps, created terraform modules to expand their current CI/CD pipelines and telemetry to use Lacework, an enterprise security tool.


Expanded our repos to include security.md's and created pipelines to write findings with PR's


Expanded both pre-commit, and post-commit tests to include dataloss checks.


Added Google SSO, and authenticator best practices to the entire org, reducing the many SSO's into one and enforcing MFA for our most privileged human accounts.


Managed and troubleshot active services with K9s, terminal, and linux knowledge


Leveraged NIST CSF, Site Reliability Engineering, and K8's to augment the security practices in AWS and make them as reliable as the services themselves, with 99.9% uptime. These were mostly OSINT tools that were catered to the company and repeatable tasks they normally hire for.




Senior Application Security Engineer / DevSecOps

FanDuel
12.2021 - 01.2024
  • Managed end-to-end security assessments of applications, identifying vulnerabilities and providing remediation guidance to development teams
  • Implemented and maintained security tools such as SAST, DAST, and dependency scanning in CI/CD pipelines to ensure secure code deployment
  • Led the design and implementation of secure coding practices and standards across multiple development teams with measurable improvement to our bug bounty report volume.
  • Conducted regular security training sessions for developers and stakeholders to increase awareness and adherence to security best practices with high quality content and labs.
  • Collaborated with cross-functional teams to integrate security into the SDLC and promote a culture of security by design in all application development efforts

Security Engineer

Oscar Health
06.2019 - 09.2021
  • Implemented and maintained security measures to protect company's network infrastructure and sensitive data from cyber threats and attacks.
  • Conducted vulnerability assessments, penetration testing
  • Wrote SAST/Unit tests, developed DAST/IAST/MAST for critical services alongside SRE.
  • Developed and enforced security policies, procedures, and best practices to ensure compliance with industry regulations and standards
  • Aided in creating new Infra-as-code modules and golden images for cloud hosted services or reimplementing existing modules securely.
  • Built custom static analysis tools for Infra-as-code based repositories.
  • Built our SIEM from scratch by myself and maintained a 1M per year licensed in AWS. This was one of our companies most critical services for security.

Security Engineer

FreeWheel
11.2017 - 05.2019
  • Created an authenticated and lean vulnerability management platform based on Nessus's API, providing bug observability and telemetry for the first time to our DevOps engineers.
  • Experience building log aggregation platforms from scratch and scaling them to accomodate 1Tb+ log throughput daily with great query response under heavy load.
  • Conducted forensic analysis of security incidents and created root cause analysis reports and post mortems. Drove remediation efforts and compliance attestations.
  • Created tooling that audited infra-as-code and terraform state files using TFSec and other CLI based security tools. This helped triage and backlog security problems to Jira/Github/Gitlab.
  • Network penetration testing.

Security Engineer

Acumera, Inc
10.2015 - 11.2017
  • Deep experience with PCI-DSS, and migrating payment services into AWS cloud hosted environments built to pass PCI audits.
  • Analyzed current security systems and identified areas for improvement or augmentation. 
  • Did CIS benchmarks and optimization of security controls for AWS environments.
  • Performed vulnerability testing and penetration testing on customer assets to identify security weaknesses with Kali Linux and gave high quality weekly vetted reports to leadership.
  • Created P1 escalations and managed live security incidents when found through analysis for our customers. Did senior technical oncall escalations and damage control for zero days and indications of compromise.

NOC engineer

DigitalOcean
07.2014 - 09.2015
  • Conducted data center operations, including physical and virtual server environments, network services, storage devices, and application infrastructure.
  • Troubleshot and resolved various network and server issues in a timely manner.
  • Installed, configured, and maintained industry standard routers, switches, firewalls, and load balancers.

Fraud Analyst

M&T Bank
03.2013 - 07.2014
  • Led a pivotal initiative to modernize fraud detection systems,  transitioning from an outdated dot-matrix printer-based system to a  sophisticated, code-based heuristic detection system using Perl.

Education

Bachelor of Applied Science - BASc - Computer and Information SystemsSecurity/Information Assurance

Hilbert College
05-2014

Skills

  • C/Python
  • Penetration Testing
  • Risk Modeling
  • Cloud Engineering
  • Kubernetes
  • Network engineering

Certification

Security+ CompTIA http://verify.comptia.org/ April 2024



CISSP ISC2 https://my.isc2.org/s/MemberVerification April 2024


Timeline

Senior Cloud Infrastructure Engineer

Swish Analytics
07.2024 - Current

Senior Application Security Engineer / DevSecOps

FanDuel
12.2021 - 01.2024

Security Engineer

Oscar Health
06.2019 - 09.2021

Security Engineer

FreeWheel
11.2017 - 05.2019

Security Engineer

Acumera, Inc
10.2015 - 11.2017

NOC engineer

DigitalOcean
07.2014 - 09.2015

Fraud Analyst

M&T Bank
03.2013 - 07.2014

Bachelor of Applied Science - BASc - Computer and Information SystemsSecurity/Information Assurance

Hilbert College
Ryan Palmisano