Application Security · Vulnerability SME
Security findings need context,
not noise.
Application Security | Vulnerability SME | AI-powered AppSec Workflows
I help enterprise teams assess, prioritize, and remediate vulnerabilities across large application portfolios. With 10 years of experience across technology, application security, vulnerability assessment, and remediation governance, I focus on turning security findings into clear risk decisions, practical remediation paths, and scalable AppSec workflows.
I also design and explore AI-powered AppSec workflows that improve triage, reduce cognitive overload, and help teams solve the right security problems with better context.
About
Bridging enterprise AppSec and intelligent remediation.
As a Subject Matter Expert in Vulnerability Assessment and remediation, I bring 10 years of experience across technology, application security, vulnerability analysis, risk assessment, and remediation guidance for enterprise applications.
My work spans DAST, SAST, enterprise penetration testing, API security, global VA compliance, security governance, and process optimization. I focus on helping teams understand which vulnerabilities matter, why they matter, and how they can be remediated in a practical, risk-based way.
At Citi, I serve as Assistant Vice President, Senior Application Vulnerability Assessment Analyst, supporting vulnerability remediation, severity assessment, risk guidance, and stakeholder alignment across global application portfolios.
Previously, as Head of Security Research at ProtectOnce, I led security research and contributed to AWS-focused cloud security work, API security, and AppSec capabilities. Before moving deeper into application security, I spent 3 years as a Project Manager in technology startups, coordinating product, engineering, delivery, and stakeholder communication.
As an Independent Security Researcher, I have reported security issues across organizations including Zoom, Atlassian, Asana, Red Hat, and Google, with multiple cases remediated. I have also received Microsoft MSRC acknowledgements and delivered technical talks on security best practices.
“The real challenge isn’t just finding vulnerabilities — it’s knowing which ones matter, why they matter, and how to get them fixed.”
Focus Areas
Where I create impact
Depth across assessment, remediation, governance, and the emerging frontier of AI-assisted AppSec.
Vulnerability Assessment & Risk Management
Enterprise-scale assessment, prioritization, and risk-based decision support across complex portfolios.
Application Security Testing
SAST, DAST, penetration testing, API security, and OWASP-aligned practices across modern application stacks.
Remediation Strategy
Lifecycle guidance, severity evaluation, stakeholder alignment, and closure-focused remediation.
Security Governance & Compliance
Global VA compliance, reporting discipline, risk tracking, and process optimization to strengthen security posture.
Cloud & API Security
Security focus across AWS environments, cloud-native architectures, API security, and enterprise systems.
AI-powered Security Workflows
Designing and exploring AI-assisted AppSec workflows for contextual triage, intelligent prioritization, remediation guidance, and better security decision-making.
Experience
Selected experience
A focused view of roles where I’ve driven security, remediation, research, and technology outcomes.
Citi — AVP, Senior Application Vulnerability Assessment Analyst
Enterprise vulnerability remediation, VA lifecycle management, severity assessment, risk guidance, and stakeholder coordination across global application portfolios.
ProtectOnce — Head of Security Research
Led research across OWASP Top 10, API security, AWS cloud security, vulnerability assessment, and modern AppSec product capabilities.
Project Manager, Technology Startups
Coordinated product, engineering, delivery, and stakeholder communication across fast-moving technology environments.
Security Researcher
Reported and responsibly disclosed security issues across organizations including Zoom, Atlassian, Asana, Red Hat, and Google, with multiple cases remediated.
Recognition
Recognized for responsible security research.
Responsible vulnerability research and technical contributions recognized by leading technology and security programs.
- Microsoft Security Response Center — acknowledgements in 2020, 2021, 2022, and 2023
- Security cases reported and remediated across Zoom, Atlassian, Asana, Red Hat, and Google
- Google Hall of Fame — responsible vulnerability disclosure
- Red Hat Vulnerability Acknowledgements / Hall of Fame 2020
- Technical talks and workshops on security best practices
Future of AppSec
Building intelligence into AppSec remediation.
Beyond day-to-day enterprise security work, I explore how AI can help AppSec teams reason through vulnerability context, prioritize remediation, and reduce cognitive overload. My focus is on designing and building AI-powered security workflows that help teams understand risk, make better decisions, and solve the right AppSec problems faster.
- AI-powered workflows that bring context to every finding
- Contextual triage that surfaces what actually matters
- Remediation guidance built around risk, ownership, and practical closure
- Modern AppSec intelligence for enterprise-scale teams
Contact
Let’s connect
Interested in Application Security, vulnerability remediation, AI-powered AppSec workflows, or security product collaboration? I’d be glad to hear from you.