California, United States
• Returned in a contract role capacity working in full-stack development in application security.
• Triage, reproduce, and remediate penetration testing findings on the C8 PLM product using Burp Suite and
Postman, working across a stack including WildFly, Node.js, Microsoft SQL Server, and Docker.
• Designed and implemented improved access control framework for finer grained authorization, as well as
authorization over object creation
• Led product wide access control list changes, allowing for finer grained security configuration without regression
impact.
• Refactored login page to a modern React component, and re-configured webpack for authenticated access control and integration with authentication frameworks (OIDC).
• Remediated email REST API endpoint vulnerabilities for phishing prevention and input sanitization.
• Developed a standalone OAuth2 authentication utility using JAX-RS to secure external API integrations, managed
integration into existing C8 PLM product.
• Migrated sensitive codebase secrets to Elytron Vault, ensuring mapping of system properties to vault secrets.
• Worked directly with customers and business consultants to translate requirements into full-stack features, owning implementation from UI to backend services, and customer environment configuration