Security Architect and Developer
Israel
Security Architect and Developer
Israel
As a systems developer and security consultant with many years of experience, I have amassed much technical knowledge, both low- and high-level, and a very good understanding of enterprise security needs.
Together with the ability to see the "big picture" while not missing the finer details, I currently provide much value to my small circle of clients, in parallel to developing a unique, innovative product for the enterprise security market that will actually solve their real problems.
Most recently, I designed, developed and managed a new product/service - or Security Software As A Service. CODEFEND from Comsec's CRC provides deep and accurate security reviews beyond anything previously possible.
Analyzing and developing quality software systems, focusing mainly on application security.
(Computer Software industry)
August 2009 — Present (5 months)
(Computer Software industry)
August 2009 — Present (5 months)
(Computer Software industry)
2007 — Present (2 years )
Frequent speaker at industry conferences, such as OWASP, RSA Conference, EasyGRC, and more. Also provided security training for banks, software companies and more - anywhere between Israel and San Francisco.
Favored topics include a wide range of security issues, from SQL Smuggling and XSS, to SDL and IdM.
Still available to provide high quality, intellectual entertainment at your next geek gathering. Book now!
(Public Company; Computer & Network Security industry)
November 2008 — August 2009 (10 months)
Comsec Group's CRC - Code Review Centre - provides the innovative CODEFEND service - a cutting-edge solution for outsourcing large-scale Security Code Reviews, delivered "As a Service", providing a cheaper, deeper, faster, and more professional approach than ever before possible with existing services.
(Public Company; Computer & Network Security industry)
July 2008 — August 2009 (1 year 2 months)
Lead consultant to a wide range of companies, on everything to do with Application Security: from building secure applications with secure architecture and secure coding, to product auditing including penetration testing, architecture and deployment reviews, security policies and guidelines, secure development lifecycles, PCI audits, training and education, and everything else.
In addition, I was responsible for internal training, product quality, and project definition, assisted with external marketing and most of the technical projects in the division.
(Public Company; Computer & Network Security industry)
January 2005 — June 2008 (3 years 6 months)
Consultant to a wide range of companies, on everything to do with Application Security: from building secure applications with secure architecture and secure coding, to product auditing including penetration testing, architecture and deployment reviews, security policies and guidelines, secure development lifecycles, training and education, and everything else.
My clients included most of the largest banks and financial institutions in Israel and Europe; telecom firms; government agencies; hi-tech companies such as Intel, Microsoft, and RSA; and more.
(Public Company; MSFT; Computer Software industry)
December 2005 — June 2006 (7 months)
Assisted the internal security team to further raise the security level of Microsoft's security products. This included design reviews, threat modeling, code reviews, and penetration tests, in addition to high-level security research.
(Government Agency; 10,001 or more employees; Computer Software industry)
March 2002 — January 2005 (2 years 11 months)
Developing, managing, and maintaining numerous software projects to meet advanced Information Security needs. Consulting to all other development projects for the Israel Police, on subjects ranging from secure coding and advanced security architecture to proper development techniques.
(Privately Held; 51-200 employees; Computer Software industry)
1998 — 2002 (4 years )
BSc , Computer Science , 1997 — 2002
CISSP , InfoSec , 2006