Hi there, I'm an Application Security Engineer who works on hands-on security work with automation platforms and programming.
At Bluebeam, I run third-party penetration tests, lead yearly STRIDE threat modeling, and maintain ISO
27001/SOC 2 compliance.
I build Python automation workflows that turn garbled data into vulnerability and remediation dashboards for developers.
In my daily work, I work on vulnerability remediation, threat monitoring, and tune Cloudflare WAF rules to catch threat actors.
In past roles, I built SAST pipelines, cleaned up AWS IAM with Terraform, and
shipped identity automation, turning findings into fast fixes.
Have a project, idea or problem you'd like to discuss?
Let's talk: [email protected]
$ cat /etc/experience.log
Experience
2024.05 to Present
Bluebeam Software, Inc.
Application Security Engineer
Managed more than 20 third-party penetration tests annually
Led security initiatives across engineering and DevOps teams
Managed three daily vulnerability scanners and coordinated rapid remediation with DevOps
Increased vulnerability remediation scores across the board by 38% in one month
Performed STRIDE threat modeling and maintained ISO 27001/SOC 2 compliance
Supported developers in integrating security throughout the SDLC
Built 7 daily Python runners for automated vulnerability dashboards and reporting
Tuned Cloudflare WAF rules for threat detection, rate limiting, bot mitigation, and abuse prevention
Managed shared intelligence across cross-functional teams to accelerate security decisions, remediation, and incident coordination
Tenable
Penetration Testing
STRIDE
Cloudflare WAF
Python
DevSecOps
ISO 27001
SOC 2
2023.05 to 2023.08
Rivian Automotive, Inc.
Enterprise Cybersecurity Engineer Intern
Built a Python pipeline that prepared Checkmarx SAST data for Tableau dashboards
Secured AWS by remediating more than 50 over-privileged IAM roles and prototyping PII database encryption with Terraform and customer managed keys
Python
Checkmarx SAST
Tableau
AWS IAM
Terraform
AWS KMS
2022.05 to 2022.08
Cisco Systems, Inc.
Cybersecurity Software Engineer Intern
Built a CyberArk dashboard using PAS Reporter, Power Automate, on-premises gateways, and SQL data workflows
Automated Active Directory onboarding and CyberArk YAML ownership management with Python, Linux, and Bash
CyberArk
Power Automate
Active Directory
Python
SQL
Linux
Bash
2023.02 to 2024.05
California State University, Los Angeles
Assistant IT Lab Consultant
IT Support
Troubleshooting
Lab Administration
$ cat /etc/education.conf
Education
California State University, College of ECST
B.S. Computer Science
Los Angeles, CA
2020 to 2025
GPA: 3.67 / Cum Laude
$ skills --list
Skills
Python
Java
NodeJS
C
PHP
SQL
AWS/GCP
Penetration Testing
$ systemctl status services
Hosted Tools
Self-hosted privacy-focused tools for security professionals and developers
$ ls ~/hobby-sites
Hobby Sites
Personal experiments and fun side projects