Security Engineering Lead at Blackhawk Network (2025-04 – Present)
- Led a team of security engineers across the Core Security Services portfolio (Product, Application, API, Perimeter, Cloud, Infrastructure Security, PKI, and DevSecOps), transforming security into an engineering organization delivering reusable capabilities at scale.
- Built an Axonius-based reporting and remediation platform that increased endpoint, server, and cloud security agent coverage to 92% across AWS, Azure, GCP, Windows, Linux, and macOS.
- Built an End-of-Life (EOL) Reporting & Package Health Platform using LangGraph, AWS Bedrock, Snyk, and OSV across 28 platforms and 517K+ package occurrences, avoiding $250K–$300K in annual third-party costs.
- Established the SOC Detection Rules Program by designing production-ready detection engineering for fraud, abuse, carding, and API attacks, achieving 100% must-have detection coverage across Tier 1 and Tier 2 applications.
- Spearheaded a 60-day PCI DSS 4.0 client-side security rollout (PCI 6.4.3 & 11.6.1) across external web properties, mitigating legal liability and audit risks under compressed timelines.
- Automated mTLS Certificate Lifecycle Management via a ServiceNow and HashiCorp Vault PKI workflow, establishing a 100% reliable, DR-ready, air-gapped CA system that eliminated manual ticket handling.
- Designed a PCI Segmentation Reporting & Enrichment platform, automating network segmentation validation across 100+ AWS accounts and reducing PCI review time from 2 weeks to 1–2 hours.
Staff Product Security Engineer at Blackhawk Network (2022-11 – 2025-03)
- Drove Secure by Design initiatives through architecture reviews, threat modeling, and secure code reviews, enabling engineering teams to remediate critical design risks early in the SDLC.
- Developed a serverless Attack Surface Management (ASM) platform using AWS EKS and custom monitoring bots to map thousands of internet-facing assets in real time to power team vulnerability research.
- Engineered a scalable microservice scanning solution using tools like Nuclei to automate dynamic asset assessment and increase vulnerability coverage across Tier 1 products.
- Engineered an in-house honeypot service deployment and targeted phishing detection engine that enabled the rapid takedown of 100+ malicious domains, significantly enhancing brand protection.
- Designed and built a Security Scorecard Platform to centralize security posture, compliance metrics, and risk reporting, providing actionable visibility into product security health.
- Led the Container Security initiative by integrating Prisma Cloud (Twistlock) into CI/CD pipelines and Amazon ECR, automating container scanning across the engineering organization.
- Implemented Amazon WAF Fraud Control to mitigate automated credential stuffing and account takeover (ATO) attacks across account creation and login workflows.
- Automated security assessments and incident investigations using Jupyter Notebook-based workflows, reducing incident response time by 80% (from 24 hours to a few hours).
Product Security Engineer at Blackhawk Network (2021-09 – 2022-10)
- Managed the rollout and lifecycle of SAST, DAST, and SCA tooling across Tier 1 and Tier 2 applications, establishing baseline security controls and high-density coverage across core builds.
- Designed a custom Jenkins DevSecOps plugin to perform post-build security scans and generate automated release-level security reports directly inside CI/CD pipelines.
- Built and matured the Perimeter Security program by deploying WAF, Bot Management, and edge filtering controls, blocking 300M+ monthly malicious requests while minimizing false positives.
- Standardized enterprise API Security by delivering runtime API discovery, schema visibility, and automated CI/CD security checks for core platforms.
- Established the initial Brand Protection program with automated spoof-domain detection and takedown workflows for external-facing applications.
- Provided Tier 3 incident response and on-call support, collaborating with Fraud, SOC, and Engineering teams to investigate threats and improve detection capabilities.
Frontend Developer at CollegeDunia (2021-04 – 2021-08)
- Led the migration from a legacy PHP/Laravel frontend to Next.js, improving page performance and interactivity by 50%.
- Engineered reusable UI component libraries and modular SCSS workflows, reducing redundant codebase overhead by 30%.
Full Stack Developer at HSG Networks (2019-04 – 2021-04)
Part Time
- Architected web and mobile applications using Next.js, React Native, and TypeScript, leveraging strict type-safety to eliminate runtime errors.
- Integrated serverless cloud backends and GraphQL APIs using AWS Amplify CLI, Cognito authentication, and DynamoDB.
Full Stack Developer at Fluorescent Inc (2018-09 – 2019-01)
Part Time
- Developed full-stack PHP/Laravel web applications with MySQL backends and custom third-party API integrations.
- Used Nominatim API, an open source solution for Google Maps API.