SENIOR DEVSECOPS ENGINEER II AT WELLTHY

I architect security automation that keeps cloud platforms compliant, observable, and resilient — so teams ship fast without compromising trust.

SCROLL
0-dayMTTRCritical vulnerability remediation
0+TeamsFull security coverage at Wellthy
0+ProgramsSecurity initiatives built from scratch
0+EngineersEnabled & coached securely

CLIENTS

Trusted by teams across healthcare, defense, education, and small business.

  • CVS Health
  • Wellthy
  • Parsons
  • UCCS
  • Resident Inspect
  • Innovative Property Solutions
  • Logan Cooper Counseling
  • Coast Party Rental

ABOUT

DevSecOps leadership that turns compliance into an engineering advantage.

I'm a security engineer who believes the best guardrails are the ones developers never have to think about. Over the past 7+ years I've built and led security programs from the ground up — standing up vulnerability management platforms, passing SOC 2 audits, running incident response, and wiring automated scanning into every stage of the pipeline.

Most of that work happened at Wellthy, where I've been the sole security lead across 7+ engineering teams for a healthcare platform handling sensitive caregiver data. Before that I scaled DevSecOps tooling for 4,000+ engineers at CVS Health, built defense-grade microservices at Parsons, and ran my own consultancy doing pentests and full-stack builds. I care about making security feel like a tailwind, not a tollbooth.

01

Automate the Guardrails

Security controls belong in the pipeline. I wire SAST, SCA, IaC, container, and CSPM coverage directly into delivery so engineers ship safely by default.

02

Measure Trust Continuously

From SIEM dashboards to SBOM registries, I centralize signal so compliance evidence, alerting, and trending risk data are always at hand.

03

Enable Every Engineer

Training, playbooks, and reusable templates turn security from a gate into a partnership. I build programs that scale good decisions across teams.

EXPERIENCE

7+ years securing SaaS platforms across healthcare, enterprise, and defense.

Wellthy

Current

Senior DevSecOps Engineer II (Lead)

Huntington Beach, CA

January 2022 — Present

Lead cloud security and compliance engineering for a healthcare caregiver platform. Consistently exceeded expectations building security programs from scratch, pairing automation with proactive response across 7+ engineering teams.

  • Led procurement, testing, contract negotiations and integration of DevSecOps Security and Cloud Security tooling into the full SDLC — SAST, SCA, IAC, Container, CSPM, Secret scanning, Compliance management, and Vulnerability Management
  • Orchestrated an automated vulnerability pipeline enhanced with ML models, pushing results to a centralized database with internal ticketing for remediation and SLA tracking
  • Led and passed multiple SOC 2 Type II audits, establishing and operationalizing controls, processes, and evidence collection to exceed compliance standards
  • Directed all penetration testing efforts for 2023, 2024, and 2025 — vendor selection, scope definition, execution oversight, and remediation follow-up
  • Architected AI-powered vulnerability remediation system using Claude API: auto-detects tickets, analyzes codebase, generates fix PRs via CircleCI cron pipeline
  • Designed LLM security firewall with prompt injection detection, PII/PHI redaction, response sanitization, and sub-200ms latency for AI-powered healthcare features
  • Maintained a 0-day Mean Time to Remediation (MTTR) for all critical and high-severity vulnerabilities through rigorous patching and escalation workflows
  • Founded Wellthy's Bug Bounty program; triaged, replicated, confirmed, and resolved all submitted findings from external security researchers
  • Managed all security incidents end-to-end: triage, containment, root cause analysis, and long-term resolution across cloud and application environments
  • Migrated SAST/SCA/secret scanning to GitHub Advanced Security (CodeQL, Dependabot, Secret Scanning); restructured GitHub admin roles with least-privilege
  • Led end-to-end CSPM tool migration: evaluated 5 platforms with live AWS PoC environments, wrote ADR, migrated all cloud integrations and alerting
  • Built and led Wellthy's first security training program for engineers, increasing adoption of secure coding practices and improving issue detection during code review

CVS Health / Aetna Health

DevSecOps Engineer → Senior DevSecOps Engineer

Denver, CO

May 2020 — January 2022
  • Promoted to Senior within 4 months; became lead security engineer for Aetna Health DevSecOps
  • Created integrations, maintained, and administrated: Datatheorem, OWASP Zap, Checkmarx CxSAST, Prisma Cloud Compute (Twistlock), NexusIQ, and Snyk
  • Built a unified portal for all security tools — easily configured and managed under a single React application hosted in AWS infrastructure
  • Created security automation microservices in Python, NodeJS, Bash, and AWS utilizing EC2, ECS, ECR, Route53, API Gateway, IAM, S3, VPC, and Lambdas
  • Supported over 4,000 engineers on Docker, Python, Security, CI/CD, Secure Architecture, Security Reviews, and Audits
  • Built and integrated a SIEM (ELK stack) into CVS infrastructure
  • Created an operational analyst team to streamline the security vulnerability management program including documentation, hiring, and training
  • Collaborated with GRC to define, implement, and remain in compliance with security controls including HIPAA and PCI-DSS
  • Led procurement, testing, and integration of new security suites
  • Facilitated technical interviews for DevSecOps engineers and Software Security Analysts
  • Built, debugged, maintained, and improved CI pipelines/CircleCI orbs in Jenkins and CircleCI
  • Created and maintained secure by default docker images for use downstream in applications

Parsons

Full Stack Software Engineer

Colorado Springs, CO

March 2019 — January 2020
  • Worked with a clearance on microservices and ETL pipelines for multiple sectors of the military
  • Created scalable object recognition microservices for images and videos with Darknet and YOLO
  • Wrote/tested RESTful services with Java and Spring
  • Scanned and remediated vulnerabilities in applications with Fortify Static Code Analysis (SAST)
  • Developed an automated test suite with Postman/Newman
  • Designed Cloud Data Enrichment pipelines
  • Transformed NLP, Data Enrichment, and Import/Export pipelines to production code

Formulated, LLC

Founder / Software Engineer

Denver, CO

January 2017 — May 2020
  • Improved client lead generation conversion rate by 79% that improved revenue by $300k
  • Created Full Stack Web Applications for small businesses that converted leads into customers
  • Contracted by companies to conduct security reviews, penetration testing, and audits
  • Created maintainable and scalable CI/CD pipelines for timely and secure updates

PROGRAMS & LEADERSHIP

Scaling secure engineering culture through enablement and repeatable playbooks.

Wellthy

Security Training Program

Built and led Wellthy's first security training program for engineers. Evaluated SCORM-compatible platforms, procured and deployed selected vendor, integrated with HRIS for compliance tracking, increasing adoption of secure coding practices and improving issue detection during code review.

Wellthy

Org-Wide Threat Modeling

Introduced and operationalized STRIDE threat modeling using OWASP Threat Dragon across 7+ engineering teams. Created data flow and authentication diagrams, documented threats and mitigations, and integrated findings directly into the SDLC.

Wellthy

Compliance & Pentest Orchestration

Led and passed multiple SOC 2 Type II audits while aligning HIPAA, NIST, and GDPR controls with automated evidence collection. Directed all penetration testing programs (web, iOS, Android) for 2023-2025 end-to-end. Founded Bug Bounty program, triaging and resolving all external researcher findings.

CVS Health / Aetna

Security Vulnerability Management Team

Created an operational analyst team to streamline the security vulnerability management program. Included documentation, hiring, and training. Facilitated technical interviews for DevSecOps engineers and Software Security Analysts.

CVS Health / Aetna

DevSecOps Community Coaching

Hosted brown bags and 1:1 sessions for 4,000+ engineers, sharing secure coding practices, Docker, Python, CI/CD pipeline patterns, and threat review rituals across consumer health product teams.

CVS Health / Wellthy

SIEM Integration & Log Aggregation

Built and integrated a SIEM (ELK stack) into CVS infrastructure. At Wellthy, negotiated and deployed SumoLogic organization-wide — aggregating audit logs from all products and cloud services with real-time alerting and cross-product correlation rules.

EXPERTISE

Tooling and practices I rely on to automate security at scale.

Security Platforms

SAST

SnykCheckmarxFortifyGitHub Advanced SecurityCodeQL

DAST

ProbelyOWASP ZAPData Theorem

SCA

SnykNexus IQGitHub Advanced SecurityWizDependency-TrackCycloneDX

Container Security

Twistlock / Prisma CloudWizClairSyft

CSPM

WizLacework

Other

PlexTracGitleaks

Cloud & Infrastructure

AWS

EC2ECSECREKSS3LambdaIAMVPCRoute 53API GatewayRDSDynamoDBElastic BeanstalkSecrets ManagerRekognitionAthenaCloudTrailCloudFrontALB

Other Cloud

Cloudflare (WAF, API Shield, Zero Trust, CDN)AzureGCP

IaC & CI/CD

TerraformDockerDocker-ComposeKubernetesGitHub ActionsCircleCIJenkins

Identity & Secrets

OktaAuth0TeleportDopplerSSO / SAML

AI & Automation

Claude APIAzure OpenAICloudflare AI GatewayLangChain / LangGraphTray.ioLogicGate

Compliance & Governance

SOC 2 Type IIHIPAANISTGDPRPCI DSSSTRIDE / OWASP Threat DragonPentest Program ManagementBug Bounty Management

Engineering

Languages

PythonTypeScriptJavaScriptNode.jsJavaBash

Frameworks

DjangoFlaskReactRelayAngularJSSpringopenCV

Data & APIs

GraphQLPostgreSQLMySQLMariaDBMongoDB

Observability

Sumo LogicELK Stack (SIEM)

Artifact Management

Nexus RepoArtifactoryElastic Container Registry

CERTIFICATIONS & LICENSES

Validated expertise across security, cloud, and field operations.

AI Security

Securiti AI — 2025

Active

AWS Security Specialty

Amazon Web Services — 2022

Terraform Associate

HashiCorp — 2022

AWS Cloud Practitioner

Amazon Web Services — 2021

FAA Part 107 Remote Pilot

Federal Aviation Administration

Active

GMRS Radio License

Federal Communications Commission

Active

PROJECTS

Hands-on builds that keep platforms secure and resilient.

Creator & Developer

Smoke Signal

Visit

iOS app enabling off-grid group communication by pairing with LoRa radios. Live GPS mapping, end-to-end encrypted messaging, emergency SOS alerts, and GPX route import — all with zero cloud dependency.

Built with Swift, currently in active development for App Store launch.

Creator & Developer

LEAP!

Visit

iOS platform jump game shipped on the App Store. Tight arcade loop tuned for one-handed play, with progression and physics tuning iterated across test builds.

Live on the App Store, built solo from prototype to release.

Creator & Developer

Cairn

Hike photos to 3D-printed topography. Feed it a folder of geotagged photos; get back an STL pair — terrain and trail — that slices cleanly on a Bambu A1 Mini for a dual-color print where the route is raised on the mountain. Extracts the track from photo EXIF, smooths GPS jitter, queries OpenTopography for a DEM covering the bounding box, then drapes the route across the terrain mesh with a configurable Z-offset so the trail reads clearly without clipping into the surface.

Python 3.12, uv, click, pydantic-settings, trimesh, rasterio, pyproj. Every stage is a standalone, idempotent CLI subcommand with inspectable intermediate artifacts (EXIF CSV, GPX, GeoTIFF, STL). Alpha — shipping first print of the Peru Ausangate trek.

Architect & Operator

Home Server Platform

150TB Unraid virtualization and NAS environment supporting 80+ users with Bitwarden, Nextcloud, Home Assistant, and custom registries.

30+ Docker services with 99.99% uptime, automated off-site backups, and Cloudflare-protected ingress.

Hardware Security Developer

Deauthentication Detector

Raspberry Pi-based device that identifies Wi-Fi deauthentication attacks and surfaces telemetry on likely sources.

Python, Node.js, MongoDB, and Aircrack-ng for real-time malicious network activity alerts.

Contributor

GraphQL-Cop (Open Source)

Added cookie authentication support and Dockerfile to the open-source GraphQL security scanner, improving CI/CD integration for authenticated endpoint testing.

Contributed upstream to improve the tool's usability in enterprise DevSecOps pipelines.

Creator & Developer

Sluice

Visit

Open-source AI governance control plane. One control plane with three ingress adapters: browser extension, LiteLLM proxy, and SDK. Cedar policy engine for policy enforcement, PII/PHI scanning via Presidio and LLM Guard, ClickHouse audit logging, and a Next.js dashboard. Open-core model targeting regulated industries.

Apache-2.0, actively maintained, CI-tested.

Creator & Developer

Preplate

iOS nutrition and meal-planning app. Macro and calorie tracking with training and rest day targets, Apple Health integration, a weekly meal planner, recipe detail views with a serving scaler and step timers, auto-generated shopping lists grouped by aisle, water and body-weight tracking, and AI coaching. Planning, tracking, cooking, and shopping in one app, not a photo-calorie logger.

Swift/SwiftUI, submitted to App Store review August 2026.

Creator & Developer

suzfit

iOS fitness tracking app for logging workouts, sets, and progress over time. Built solo end to end, from data model through App Store submission.

Swift/SwiftUI, submitted to App Store review August 2026.

BOOK

Helping others break into DevSecOps.

Breaking into DevSecOps book cover

Breaking into DevSecOps

A Practical Guide for Launching Your Career in Secure Software Delivery

A hands-on guide covering everything from security fundamentals to building DevSecOps pipelines, threat modeling, and landing your first role. Written for engineers, career switchers, and anyone looking to break into the field.

Kindle — $9.99Paperback — $19.99

PHOTOGRAPHY

Beyond the terminal.

I carry a camera on every adventure. Photography is my creative counterbalance to security engineering — both demand patience, precision, and an eye for what others miss.

Panoramic landscape
Landscape photography
Nature photography
Aerial drone photography
Travel photography
Couples portrait
Adventure photography
Coastal photography
Scenic photography

GET IN TOUCH

Let's build something secure.

I partner with teams that treat security as a core product feature. Whether you're scaling a healthcare startup, preparing for audit, or modernizing enterprise pipelines — let's talk.