
Managing Consultant - Foundstone Professional Services
Greater Atlanta Area

Managing Consultant - Foundstone Professional Services
Greater Atlanta Area
Dean is a Managing Consultant at Foundstone. He is responsible for conducting web application penetration testing, threat modeling, code reviews, secure software development lifecycle (S-SDLC) design and implementation, and project management. Dean also provides client education services as a lead instructor of these Foundstone courses: Building Secure Software, Writing Secure Code: Java/J2EE, Writing Secure Code: ColdFusion and Ultimate Web Hacking.
Dean has over ten years of software development experience in a variety of industries, including banking, education, and quality control. Since 2001, he has focused on secure software development and web application security. Prior to working at Foundstone, Dean held the position of manager of web application security for a corporate cash-management application service provider. In this position, he implemented the company’s first secure software development and deployment guidelines, development frameworks to support secure coding paradigms, tools used for the semi-automated remediation of application vulnerabilities, and static code analysis tools to expedite conducting secure code reviews.
Dean co-founded and remains active in the Atlanta ColdFusion User Group (ACFUG) and is an active member of the Open Web Application Security Project (OWASP) Atlanta Chapter.
Dean is a frequent speaker at development conferences including Cf.Objective() and The Rich Web Experience, No Fluff Just Stuff, and user groups such as ACFUG and the Atlanta Java Users Group.
Certifications:
Certified Information Security Systems Professional (CISSP)
Certified Ethical Hacker (CEH)
Threat Modeling
Secure Code Reviews
Developing Secure Applications
Secure Software Development Lifecycle Implementation
Web Application Penetration Testing
Teaching Software Security Principles & Practices
Project Management
ColdFusion
Perl
Java/J2EE
RegEx
(Sports industry)
June 2008 — Present (1 year 2 months)
Fitness instructor for early AM classes at Bitsy Grant Park in Atlanta, GA.
(Privately Held; 51-200 employees; MFE; Computer & Network Security industry)
February 2005 — Present (4 years 6 months)
Responsible for conducting web application penetration testing, secure source code reviews, threat modeling, Secure SDLC program development, software security course development and training in software security best practices. Project manager for Foundstone projects predominantly in the south eastern US.
(Privately Held; 1-10 employees; Computer Software industry)
September 2003 — Present (5 years 11 months)
Seeking business opportunities in software and web application security.
(Public Company; 501-1000 employees; DGIN; Computer Software industry)
May 2001 — February 2005 (3 years 10 months)
Implemented MVC architecture with ColdFusion 5 to address design deficiencies and encourage common designs and naming conventions to improve maintainability, efficiency and code reuse.
Provide technical guidance to developers on secure coding practices and designs.
Produce development coding standards for web applications and security awareness classes for all developers.
Conduct web application penetration testing through manual and automated methods
Supporting the installation and troubleshooting of Magnets cash management system, responding to urgent client requests for support with quick turnaround times.
(Computer & Network Security industry)
1997 — 2000 (3 years)
B.A. , Biology , 1991 — 1993
Craft beer, homebrew, hiking, Leukemia & Lymphoma Society fundraising, running, trail running