Computer Security Researcher
Portland, Oregon Area
Computer Security Researcher
Portland, Oregon Area
I have a wide range of professional experience in computer security. I have experience performing post-intrusion forensic analysis on windows, linux, and solaris machines. I have been responsible for securing and monitoring a large network topology while at Portland State University. I also have professional experience securing a large scale medical product with many backend servers and many thousands of embedded devices per deployment. This involved the use of various source code analysis techniques, as well as web, vpn, and network security analysis.
I have also worked on many personal projects involving network scanning, network traffic dissection, and static analysis.
code auditing, network topology analysis, network penetration, cryptography, network automation
(Computer & Network Security industry)
February 2009 — Present (10 months)
We are currently designing solutions for securely deploying large scale networks for the storage and sharing of electronic medical records.
(Public Company; 10,001 or more employees; INTC; Semiconductors industry)
September 2007 — May 2008 (9 months)
Designed and ran multiple security tests for a large scale medical product. I also was involved in many of the higher level design processes.
(Public Company; 10,001 or more employees; INTC; Semiconductors industry)
May 2007 — September 2007 (5 months)
Designed and implemented multiple security modules for an embedded medical device. Specifically, xml-rpc modules in c++ for managing firewall, vpn, and database crypto configurations. I also used klocworks to perform static analysis on the source tree, and implemented many security tweaks at the operating system level.
(Computer & Network Security industry)
February 2007 — April 2007 (3 months)
I helped design strong authentication technologies for generic usage in web applications.
(Educational Institution; Computer & Network Security industry)
August 2005 — February 2007 (1 year 7 months)
Forensic analysis of compromised linux, solaris, and windows machines
Designed and wrote an automated incident response system in PHP
Constant scanning of the network topology
Deployed mod_security and DenyHosts on critical web and ssh servers
Gave training on tracking network intrusions
(Public Company; 1001-5000 employees; CMOS; Semiconductors industry)
September 2001 — June 2002 (10 months)
I was an intern in the SETI group at credence. My tasks were mostly imaging machines, and creating/deploying software builds for various tools that might be wanted by the software engineering team. This sometimes involved tinkering with the active directory tree etc.
So, from how I understand it, I worked for a guy who worked on a team that supplied software for the group that wrote software for the testers that tested the microprocessors for the customers.
2002 — 2006
rainsec