Mariia T
Senior Application Security Engineer
Competenze

Consulta i miei servizi


Portfolio
Esperienza lavorativa
Senior Application Security Engineer
Dell • Full time
Sep 2023 - Oct 2025 • 2 yrs 1 mo
- Strategic Security Leadership: Define and execute the organization’s application security strategy, aligning initiatives with business objectives and long-term risk management frameworks. Develop governance policies to ensure compliance with industry standards and regulations such as OWASP, NIST, and GDPR. - Collaboration with Developers: Partner with development teams of all seniority levels to address vulnerabilities, integrate security tools into CI/CD pipelines, and foster a proactive security culture. Design and implement impactful programs such as Capture the Flag (CTF) events, Secure Coding Tournaments, and tailored secure development training. - Risk and Vulnerability Management: Conduct advanced security assessments, including SAST, SCA, IaC, API security, and DAST. Facilitate penetration testing, manage vendor relationships, and track remediation efforts using tools like Jira to ensure timely resolution of findings. - Team Leadership and Development: Build and mentor high-performing security teams, fostering a culture of continuous learning. Provide strategic guidance and hands-on expertise to empower developers and improve the organization’s security posture. - Metrics and Reporting: Develop and present key performance indicators (KPIs) to senior leadership, demonstrating the effectiveness of security initiatives and their impact on reducing risk. - Executive Communication and Budgeting: Communicate complex security issues clearly to executives and non-technical stakeholders. Oversee budgets and resource allocation for application security programs to ensure optimal efficiency and alignment with business goals.
Senior Systems Security Engineer
EPSoft • Full time
Aug 2021 - Sep 2023 • 2 yrs 1 mo
• Run SAST, SCA, IaC, and API security scans on in-house developed code (tools: Checkmarx, CheckmarxOne). Triage scan results to identify true positives and false positives. Help developers to comprehend results and come up with the best patch options. • Advise developers on the nuances of setting pipelines in Azure DevOps (ADO) to automate the scanning process. • Developed interactive Information Security training for EPAM Summer School. Taught more than 50 students per session. • Performed threat modeling and prepared a recommendations report. Conducted baseline assessment and application design review; created design documents (DFD and C4 diagrams); created an Access control concept.
Information Security Analyst
OANDA • Full time
Oct 2020 - Jun 2021 • 8 mos
Worked with on-prem and cloud-native security tools including Rapid7 and Splunk. Validated remediations of vulnerability findings using Nmap, SQLmap, and Burp Suite. Managed regional compliance with ISMS frameworks such as Risk Management, GDPR, and SOC2. Conducted security awareness sessions and onboarded over 200 employees.