Product Security Engineer @ SproutXP
Building security in, not bolting it on.
- π‘οΈ Product Security Engineer at SproutXP, partnering with engineering teams from design through release.
- π I spend my days on secure design reviews, threat modeling, security architecture, and vulnerability management.
- π€ Big believer in paved roads β secure defaults and shared libraries beat security review bottlenecks.
- π Always learning: authentication & authorization design, cryptography in practice, and multi-tenant isolation.
- π¬ Ask me about product security, secure SDLC, security architecture, or building a bug bounty program.
Languages
Security
Cloud & Infra
| Area | Focus |
|---|---|
| ποΈ Security Architecture | Secure design reviews on new products and features |
| π§΅ Threat Modeling | Abuse cases and trust boundaries before a line is written |
| π AuthN / AuthZ | Identity, session, and access control design |
| π οΈ Secure Defaults | Guardrails and libraries that make the safe path the easy path |
| π Vuln Management | Triage, risk-based prioritization, and driving fixes to done |
"The safest code is the code that was designed not to be dangerous."