I lead the charge in building, scaling, and optimizing Application Security programs that protect enterprise applications from code to cloud. With experience spanning SAST, DAST, SCA, CWPP, WAF, and AI-driven security initiatives, I partner with developers, architects, and leadership to weave security seamlessly into modern development lifecycles.
Security should be an enabler, not a blocker. My mission is to make secure development the easiest path forward.
▸ AI-enhanced vulnerability detection and remediation
▸ Secure adoption and governance of AI-generated code
▸ Frictionless developer security experiences
▸ Application Security and AI risk management convergence
▸ Threat modeling for modern cloud-native architectures
▸ Cross-team collaboration for secure delivery
▸ Data-driven security program maturity and measurement
▸ Researching emerging attack techniques and defensive controls
▸ A pervasive shift-left security culture
▸ Scaling security through automation and intelligent workflows


