Senior Technical Security Engineer at AOL
Washington D.C. Metro Area
Senior Technical Security Engineer at AOL
Washington D.C. Metro Area
My career in information systems has offered a wide variety of opportunities which have all contributed to my knowledge in Technical Security Engineering. My early years were focused on building web applications. As a graphic designer and HTML programmer I learned about the client portion of the web equation. Later, as a ASP and PHP developer, I learned about the web server, active scripting languages, and databases. My personal consulting business offered me the opportunity to delve into Networks, Operating Systems, and Hardware. Thanks to corporate training programs with past employers, I've been able to pursue my goal of becoming an independent security researcher specializing in identification, remediation, and prevention of vulnerabilities in web based technologies. As of recently, I've been getting back into the web development world building several web based applications leveraging public APIs and web services.
Network based, Web application, API, and host penetration testing, Operating System Hardening, Secure Communications Management, Firewall configuration and testing, Reverse Engineering, Malware analysis, PHP/MySQL Development, Content Management System setup and management, Community Building techniques, Website Usability.
(Public Company; 10,001 or more employees; Computer & Network Security industry)
May 2006 — Present (3 years 3 months)
-Perform technical security assessments of web applications, desktop applications, hosts and services, and network architectures for the Time Warner enterprise.
-Developing the web application security assessment methodology based on industry standards and AOL specific policies in an effort to standardize, streamline, and expand the team's existing capabilities.
-Developing and executing outreach and communications plan for disseminating security related information through informal publications, formal policies, standards, and baselines, and a corporate security training program.
-Created and marketed the Open-ITSec blog to disseminate IT Security related news and information in a rapid and informal manner.
-Representing IT security interests on committees ensuring that appropriate security measures are implemented throughout the ODLC.
-Coordinating the integration of security requirements into the SDLC with development teams, project stakeholders, and upper management.
(Non-Profit; Myself Only; Sports industry)
January 2006 — Present (3 years 7 months)
I started www.dcwake.com as a resource for local DC area wakeboarders. Since January 2005 the site has seen 250 registered users, photo and video media, reviews, local wakeboarding event growth, and 5000 monthly visitors averaging 840000 monthly hits. As "The Main Guy" I'm responsible for maintaining and expanding a custom Joomla based Content Management framework. In addition to the technical work, I also organize gatherings, write articles, provide access to my boat, teach inexperienced rides, and generally lead the entire local wakeboarding community.
Web Application Security, Web Application Development, Graphic Design, Network Security, Computer Security, Application Security, Reverse Engineering, Wireless Technologies, Community Building, Content Management Systems, Open Source Technologies. Wakeboarding, Boating, Home Renovations.
CISSP