United States
With over a year and a half of focused experience in information security, I am a proactive and goal-oriented Information Security Engineer. With a foundation fortified by a Master’s degree from Carnegie Mellon University, I bring a robust blend of academic insight and practical experience gained through impactful roles at VMware, Amazon, the Software Engineering Institute, and now Tenable. In my current role as a Associate Security Engineer at Tenable, I partner closely with sales teams and customers to translate complex security challenges into actionable solutions. I leverage deep expertise in Exposure Management to help organizations reduce risk, strengthen security postures, and align technical strategy with business outcomes. By combining technical acumen with strong communication skills, I bridge the gap between engineering and executive stakeholders, ensuring clarity, trust, and measurable value throughout the sales cycle. My career reflects adaptability and a commitment to staying ahead of evolving security challenges. I strive for operational excellence, innovative problem-solving, and delivering measurable impact. Beyond technical expertise, I pride myself on being a collaborative, results-driven professional who thrives in fast-paced, dynamic environments.
• Manage long-term, ongoing continuous monitoring and FedRAMP regulatory compliance programs that involve 200+ cross-functional stakeholders. Partner with product and asset owners to assess vulnerabilities, enforce SLA compliance, and mitigate risk. • Contribute to FedRAMP and continuous monitoring leadership team meetings. • Regularly conduct security control assessments, vulnerability assessments, and reporting. • Provide engineering and product support to the application security, cloud engineering, and software development teams, as well as project managers and vendor stakeholders.
• Collaborated extensively with Business Units, Red Team, Product Security, external researchers, and customers, playing a pivotal role in remediating vulnerabilities across 1M on-prem and cloud assets, ensuring enhanced security postures. • Leveraged deep expertise to furnish comprehensive evidence and informed support pivotal for adherence to global audits such as PCI-DSS and SOC2 Type 2, fortifying organizational compliance frameworks. • Engaged proactively across various security teams, employing a meticulous approach in scanning and diminishing the company’s attack surface, leveraging both off-the-shelf and bespoke internal tools to augment security resilience. • Innovated operational efficiencies by developing a Python module dedicated to bolstering automation projects. This initiative was instrumental in empowering Business Units through self-service capabilities and significantly curtailed manual operational tasks. • Contributed substantively to the implementation of Brinqa, a strategic move aimed at optimizing risk management processes, facilitating a more robust and agile organizational risk response mechanism.
• Enhanced the efficacy and reach of an internal vulnerability detection tool by innovatively developing automated checks that broadened the tool's coverage, enabling the more proficient identification of vulnerable resources within AWS accounts, and ensuring a more secure and resilient infrastructure. • Authored comprehensive and detailed documentation, enriched with illustrative UML diagrams that provided production teams with clear, concise, and actionable insights, facilitating effective remediation of identified vulnerabilities and bolstering organizational cybersecurity postures • Engaged in a valuable learning and development opportunity by shadowing internal penetration tests. This experience allowed for the absorption of practical knowledge and expertise, contributing to professional growth and the enhancement of penetration testing competencies.