Apr 2024 to Present
CurrentSoftware Security Engineer, Product Security
University of Maryland · College Park, MD
Own application security across the development lifecycle for research software that is exposed to external users, and build production features on the same codebase.
- Cut software defects by 50% through OWASP Top 10 code review and remediation of XSS, insecure design, input validation, and cross origin weaknesses, using server and client side validation, CORS hardening, and DOM safe content handling.
- Run manual and dynamic testing with Burp Suite across API endpoints, authentication and authorization flows, session handling, input validation, CORS behavior, and business logic, then reproduce findings and confirm real impact before remediation.
- Embed security into the SDLC by reviewing attack surface, trust boundaries, REST APIs, user controlled inputs, file processing paths, and externally exposed functionality at design, development, and release.
- Lead threat modeling and security design reviews across frontend and backend data flows, service integrations, and privilege boundaries, turning high risk attack paths into concrete engineering controls.
- Design token authenticated Flask REST APIs and access controlled workflows that strengthen authentication, authorization, and session boundaries for externally accessible functionality.
- Partner with developers on triage, root cause analysis, code level fixes, and retesting before release to confirm remediation and prevent regression.
- Reduced application response time by 50% while building production services with React, Flask, Python, REST APIs, and Docker.
- Standardized releases with GitHub Actions, CI/CD, Docker, and shell automation, improving deployment reliability, logging visibility, and secure configuration management.
- Burp Suite
- OWASP Top 10
- Threat Modeling
- Flask
- React
- Python
- Docker
- GitHub Actions