Application Security
Secure SDLC, SAST and DAST, dependency scanning, OWASP Top 10, threat modeling and architecture reviews.
Application Security · DevSecOps · Gen AI
Building secure software.
Leading teams. Advancing AI in AppSec.
I bring engineering leadership and application security together to protect enterprise platforms—from the first line of code to runtime.
01 / About
From enterprise software and identity platforms to cloud modernization and AI-assisted security.
I lead AppSec and DevSecOps teams across development and runtime environments. My work connects security strategy with engineering execution: embedding controls in delivery pipelines, modernizing enterprise systems, and helping engineers put large language models to work in vulnerability discovery and exploit testing.
Reduction in high and critical vulnerabilities through integrated scanning and compliance checks.
Fannie MaeUsers supported by a registration and SSO platform across seven high-traffic websites.
Scripps Networks Interactive / CognizantFounded an enterprise DevOps framework recognized with multiple innovation awards.
Fannie Mae02 / Recent focus
Applying frontier models to security analysis and automated testing within enterprise AppSec workflows.
Fannie Mae / Current work
I work with engineering teams to bring AI-assisted analysis into application security, with a focus on actionable findings and reducing false positives.
Using Claude Opus 4.8 and GPT 5.5 Cyber to find application vulnerabilities through automated analysis workflows.
Applying LLM models to automated exploit testing as part of application security evaluation.
Participating in Project Glasswing testing at Fannie Mae using the Mythos 5.1 model to evaluate application security capabilities.
03 / Expertise
A foundation in software architecture, strengthened by hands-on security leadership and enterprise delivery.
Secure SDLC, SAST and DAST, dependency scanning, OWASP Top 10, threat modeling and architecture reviews.
LLM-assisted vulnerability discovery, security analysis and automated exploit testing in AppSec workflows.
CI/CD security integration, shift-left and shift-right programs, enterprise frameworks and delivery standards.
AWS architecture, infrastructure as code, cloud-native microservices and migration from on-premises systems.
Enterprise Java, backend and frontend systems, identity platforms, design reviews and performance engineering.
Distributed team leadership, coaching and mentoring, roadmaps, executive collaboration and agile delivery.
04 / Experience
Building enterprise systems. Growing engineering teams. Making security part of how software ships.
View full résumé ↓Fannie Mae · Herndon, VA
Lead AppSec and DevOps teams across development and runtime. Founded the FLASH framework, integrated scanning into delivery workflows, and led cloud modernization. Recent work includes LLM-assisted vulnerability discovery, automated exploit testing and Project Glasswing testing.
Capital One · McLean, VA
Led secure cloud-native application delivery. Partnered with product and engineering leaders on roadmaps and reinforced engineering standards through design and code reviews.
WealthEngine · Bethesda, MD
Architected backend and frontend systems, managed and mentored the Data Engineering team, and introduced tools to improve productivity and cost efficiency.
Scripps Networks Interactive / Cognizant
Managed 10 onshore and offshore developers. Led registration and SSO architecture supporting 2+ million users across seven websites, along with service integrations and performance improvements.
Pebblepath Technologies · Chennai, India
Led technology research, solution evaluation and the core development team. Worked with the CEO on roadmaps and client proposals while mentoring developers.
Interpress India / Dailythanthi · Chennai, India
Developed reusable code for the Common module of a media ERP application.
Certified Information Security Manager
ISACA · 2022
Associate certification
2019
Associate certification
2020
First Class · University of Madras
2001–2005
Selected tools & technologies
05 / Connect
Connect with me about application security leadership, DevSecOps transformation and AI in security engineering.