About

Product security leader with 15+ years in information security, most recently at Salesforce leading multiple application and platform security teams, founding a systemic security risk function, and playing key roles in several platform-wide risk reduction programs. A former hands-on practitioner who engineered an access control testing tool that uncovered 500+ authorization bugs, and who led the initiative that cut security assurance toil by nearly 50% across 1,400+ engineering teams, now bringing that depth to organizational security strategy and team leadership.

Core Competencies

Leadership & Strategy

  • Team Building
  • Talent Development
  • Security Strategy
  • Charter Ownership
  • Executive Reporting
  • Cross-Functional Leadership

Security Engineering

  • Application Security
  • Web Security
  • Security Architecture
  • Design Review
  • Authentication
  • Authorization
  • Access Control
  • Threat Modeling
  • Penetration Testing
  • Secure Code Review
  • PKI

Programs & Tooling

  • Product Security Assurance
  • Secure SDLC
  • AI Security Risk
  • Attack Surface Management
  • SAST
  • DAST
  • CI/CD Security
  • Code Signing

Technical

  • Python
  • Java
  • C/C++
  • JavaScript

Experience

Salesforce, Inc.

Director, Product SecuritySan Diego, CA (Remote) · Apr 2023 to Present
  • Systemic Risk Function: Founded a systemic security risk function, writing its charter and building a dedicated product security team that drove platform-wide risk remediation, conducted external attack surface research, and helped shape the strategy for standing up an external attack surface management program.
  • Frontier Model Risk Program: Helped expand security control coverage for AI-discovered and AI-amplified risks across multiple business units by strategically shaping the systemic risk workstream of a frontier model risk program, authoring its program definition and building its executive reporting view.
  • Organizational Leadership: Led three successive product security teams of 10+ security engineers each, covering Sales, Service, and Platform Services security assurance, then secure build and developer infrastructure security, then core platform product security, setting strategy and technical direction while standing up coverage for every new area.
  • Talent Development: Built a bench of senior technical talent across three teams by mentoring engineers through hard security design and architecture problems, championing multiple promotions into senior levels up to Principal.
  • Incident Response: Served as the product security decision owner on high-severity security incidents, leading the team's response, partnering cross-functionally on containment, root cause analysis, remediation, and executive communication, and turning lessons learned into durable control improvements.
Product Security PrincipalSan Diego, CA (Remote) · Apr 2022 to Apr 2023
  • Assurance at Scale: Cut security assurance process toil by nearly 50% across 1,400+ engineering teams and 5,000+ developers by leading a strategic initiative for a 40+ engineer security organization, moving Salesforce's core platform and cloud engineering organizations onto a component-based security assurance platform, helping define its software component model, and streamlining risk assessment intake surveys.
  • Platform Standards: Founding member of the platform access control design review board, owning security standards for platform object access control, privilege escalation, and implicit access enforcement that were adopted across the platform.
  • Sales Cloud Assurance: Continued as the primary security advisor for Sales Cloud, leading design and code security assessments across its product portfolio.
Product Security LeadSan Diego, CA (Remote) · Jun 2020 to Apr 2022
  • Access Control Hardening: Reduced guest and external user data exposure risk across the Salesforce platform as a core contributor to a platform-wide access control hardening program. Engineered an access control testing tool that covered 1,600+ platform objects, and filed and drove 500+ authorization bugs to closure.
  • Sales Cloud Assurance: Served as the primary security advisor for Sales Cloud, leading nearly 500 design and code security assessments across its product portfolio.

Illumina, Inc.

Senior Staff Information Security EngineerSan Diego, CA (Onsite) · Apr 2020 to Jun 2020
Staff Information Security EngineerSan Diego, CA (Onsite) · Apr 2016 to Apr 2020
  • Code Signing and PKI: Built an internal code signing service integrated with CI/CD, signing 50 to 100 executables per day across EXE, MSI, JAR, APK, and RPM formats, and managed the PKI and HSMs behind it, including root and intermediate CAs and instrument platform keys.
  • Product and Application Security: Led product and application security within the cybersecurity team, running design and architecture risk reviews for cloud services across roughly 100 developers and performing manual web application penetration tests that uncovered and helped fix critical vulnerabilities in public-facing infrastructure.
  • Secure SDLC: Drove secure coding, SAST, and DAST adoption across instrument and cloud product teams, set OS security requirements for Windows and Linux instruments, including Windows SRP and SELinux hardening, and guided teams on OWASP, NIST, HIPAA, and FDA requirements.

Qualcomm Technologies, Inc.

Senior Product Security EngineerSan Diego, CA (Onsite) · Feb 2011 to Mar 2016
  • IoT and Platform Security: Ran threat and risk analysis and security code review for home networking, IoT, and mobile products, from TrustZone (QSEE) trusted applications and low-level system services to web interfaces.
  • Secure Design: Designed the security protocol for an over-the-air software licensing and activation service, defined secure default configurations for OpenWRT-based router firmware, and helped product teams embed security into their development lifecycle.

Earlier Experience

  • Cigital, Inc.: Associate Consultant Intern, Sterling, VA (Onsite), 2010. Manual and automated penetration testing for a banking client.
  • Infosys Technologies Limited: Software Engineer, Pune, India (Onsite), 2007 to 2009. Feature development and testing for the IBM Cognos business intelligence suite.

Education & Recognition

  • M.S. Information SecurityGeorgia Institute of Technology.
  • B.E. Computer EngineeringDharmsinh Desai University, First Class with Distinction.
  • Qualstar AwardQualcomm, for exceptional contributions to two projects.