Mariia T

@first21seconds

Senior Application Security Engineer

Israel
Inglês, Polonês, Russo
Algumas informações são exibidas no idioma inglês.
Sobre mim
I am a Senior Application Security Engineer with hands-on ownership of AppSec across multiple products. I specialize in threat modeling, architecture reviews, and manual vulnerability validation. I have deep experience building SSDLC programs including SAST, SCA, and DAST within regulated financial environments like SOC 2. I am comfortable working with new attack surfaces and AI-driven systems.... Saiba mais

Habilidades

f
first21seconds
Mariia T
offline • 
Tempo médio de resposta: 2 horas

Conheça meus serviços

Programação e Tecnologia
I will perform threat modeling of your system
Programação e Tecnologia
I will design your vulnerability management program and slas

Portfólio

Experiência profissional

Dell

Senior Application Security Engineer

Dell • Período integral

Sep 2023 - Oct 20252 yrs 1 mo

- Strategic Security Leadership: Define and execute the organization’s application security strategy, aligning initiatives with business objectives and long-term risk management frameworks. Develop governance policies to ensure compliance with industry standards and regulations such as OWASP, NIST, and GDPR. - Collaboration with Developers: Partner with development teams of all seniority levels to address vulnerabilities, integrate security tools into CI/CD pipelines, and foster a proactive security culture. Design and implement impactful programs such as Capture the Flag (CTF) events, Secure Coding Tournaments, and tailored secure development training. - Risk and Vulnerability Management: Conduct advanced security assessments, including SAST, SCA, IaC, API security, and DAST. Facilitate penetration testing, manage vendor relationships, and track remediation efforts using tools like Jira to ensure timely resolution of findings. - Team Leadership and Development: Build and mentor high-performing security teams, fostering a culture of continuous learning. Provide strategic guidance and hands-on expertise to empower developers and improve the organization’s security posture. - Metrics and Reporting: Develop and present key performance indicators (KPIs) to senior leadership, demonstrating the effectiveness of security initiatives and their impact on reducing risk. - Executive Communication and Budgeting: Communicate complex security issues clearly to executives and non-technical stakeholders. Oversee budgets and resource allocation for application security programs to ensure optimal efficiency and alignment with business goals.

Senior Systems Security Engineer

EPSoft • Período integral

Aug 2021 - Sep 20232 yrs 1 mo

• Run SAST, SCA, IaC, and API security scans on in-house developed code (tools: Checkmarx, CheckmarxOne). Triage scan results to identify true positives and false positives. Help developers to comprehend results and come up with the best patch options. • Advise developers on the nuances of setting pipelines in Azure DevOps (ADO) to automate the scanning process. • Developed interactive Information Security training for EPAM Summer School. Taught more than 50 students per session. • Performed threat modeling and prepared a recommendations report. Conducted baseline assessment and application design review; created design documents (DFD and C4 diagrams); created an Access control concept.

OANDA

Information Security Analyst

OANDA • Período integral

Oct 2020 - Jun 20218 mos

Worked with on-prem and cloud-native security tools including Rapid7 and Splunk. Validated remediations of vulnerability findings using Nmap, SQLmap, and Burp Suite. Managed regional compliance with ISMS frameworks such as Risk Management, GDPR, and SOC2. Conducted security awareness sessions and onboarded over 200 employees.