Services
Video meeting . 15 mins
Discovery Call
Let's explore solutions for AppSec Challenges
About me
I currently work as a Cybersecurity Engineer at Altair, specializing in Application and Product Security, DevSecOps, Cloud Native Security, Software Supply Chain Security, and Penetration Testing. I focus on transforming the Software Development Lifecycle (SDLC) into a Secure Software Development Lifecycle (SSDLC).
I have implemented various secure software development activities, including SAST, SCA, DAST, Software Supply Chain Security, Cloud Native Security, Application Security Orchestration and Correlation (ASOC), WAF, etc., throughout the software development and deployment process by using well-known tools like Veracode, Fortify WebInspect, Dependency Check, Dependency Track, OWASP ZAP, DefectDojo, Prisma Cloud, Cloudflare, Rapid7, Jfrog, etc.
With my expertise in Product Security, I am passionate about helping organizations improve their application security posture while delivering high-quality products. I focus on implementing industry best practices and standards (NIST 800-218 Secure Software Development Framework (SSDF), OWASP SAMM, DSOMM, ASVS, and SCVS) for building, expanding, and managing the Application Security program to ensure robust security throughout the software development lifecycle.