Senior Security Strategist at Microsoft
Greater Seattle Area
Senior Security Strategist at Microsoft
Greater Seattle Area
(Public Company; MSFT; Computer Software industry)
September 2008 — Present (1 year 4 months)
I have joined the Security Development Lifecycle (SDL) team to help drive crucial elements of our SDL outreach effort. My primary responsibility is managing our relationships with security consulting and training partners in the SDL Pro Network. I am additionally tasked with ongoing analysis of the SDL – with a goal of assisting industry verticals that are looking to apply the SDL in critical computing scenarios. I continue to serve as lead subject matter expert in the US National Body for the ISO work item 29147 "Responsible Vulnerability Disclosure".
(Public Company; 10,001 or more employees; MSFT; Computer Software industry)
April 2007 — August 2008 (1 year 5 months)
At Microsoft, I have created and lead several new programs that expand the mission and capabilities of the Microsoft Security Response Center, including but not limited to:
Defend The Flag (DTF) training program: Trains IT Professionals on the basics of attack and Windows defense
Microsoft Vulnerability Research (MSVR): Formalizes Microsoft’s Responsible Disclosure of third-party vulnerabilities and establishes our role in protecting customers at the platform level.
Acted as subject matter expert on Responsible Disclosure and CVSS on behalf of Microsoft.
Established a role as a Trusted Advisor and cross-group liaison both within Microsoft and externally with researchers, partners, and customers.
Leveraged technical security background and consulting skills to bring true risk assessment to the Ecosystem Strategy Team.
(Public Company; 10,001 or more employees; SYMC; Computer & Network Security industry)
March 2006 — April 2007 (1 year 2 months)
I continue to provide Application Security Assessments, penetration testing, architecture and code reviews, and business development for Symantec Professional Services.
I also developed and oversee the Symantec Vulnerability Research Program:
http://www.symantec.com/research
(Public Company; 10,001 or more employees; SYMC; Computer & Network Security industry)
October 2004 — February 2006 (1 year 5 months)
I joined the company formerly known as @stake, prior to its purchase by Symantec, as a Senior Security Architect specializing in application security. I have performed application penetration testing, software design and code reviews, while developing long term strategic partnerships with our clients.
(Privately Held; 51-200 employees; Computer & Network Security industry)
March 2004 — October 2004 (8 months)
(Self-Employed; 1-10 employees; Computer & Network Security industry)
2000 — March 2004 (4 years )
Performed independent security consulting for clients throughout the San Francisco Bay Area. Industries in which I performed security consulting services include finance, health care, online commerce, networking technology, and software design.
(Public Company; 51-200 employees; Computer & Network Security industry)
2001 — 2002 (1 year )
(Computer & Network Security industry)
1999 — 2000 (1 year )
(Computer & Network Security industry)
1995 — 1999 (4 years )
Security vulnerability research, Secure Development Lifecycle, reverse engineering, quantum teleportation.