Product Security Engineer @ SproutXP
Building security in, not bolting it on.
- 🛡️ Product Security Engineer at SproutXP, partnering with engineering teams from design through release.
- 🔎 I spend my days on secure design reviews, threat modeling, security architecture, and vulnerability management.
- 🤖 Big believer in paved roads — secure defaults and shared libraries beat security review bottlenecks.
- 📚 Always learning: authentication & authorization design, cryptography in practice, and multi-tenant isolation.
- 💬 Ask me about product security, secure SDLC, security architecture, or building a bug bounty program.
Languages
Security
Cloud & Infra
| Area | Focus |
|---|---|
| 🏗️ Security Architecture | Secure design reviews on new products and features |
| 🧵 Threat Modeling | Abuse cases and trust boundaries before a line is written |
| 🔑 AuthN / AuthZ | Identity, session, and access control design |
| 🛠️ Secure Defaults | Guardrails and libraries that make the safe path the easy path |
| 📋 Vuln Management | Triage, risk-based prioritization, and driving fixes to done |
"The safest code is the code that was designed not to be dangerous."