Building Ramp's approach to security engineering where we find ways to earn user trust (and save them time and money).
We fix problems in code+infrastructure, build systems to reduce the likelihood of new issues, own security-critical product surfaces like authentication + authorization, and ship security-adjacent product features.
Plotted Ramp’s initial approach to product security. Improved foundational components of our product like session management, and re-worked development processes like dependency management and deployment. Operationalized Ramp’s bug bounty program and penetration testing program.
Found and fixed vulnerabilities. Developed new technical primitives to mitigate classes of issues while enabling product engineering teammates to move faster.
Technical lead for NBCU-wide rollout of multi-factor authentication. Built AWS reference architectures and collaborated with teams to migrate towards them. Created detections for major events.