Manager, Proactive Security (Application Security) - Current
- Joined AWS Security's Proactive Security organization as a Manager. Proactive Security performs security reviews of new product launches and features, based on a traditional SDLC program. The team supported engineering teams, primarily in the spaces of Identity, Observability, Monitoring, Analytics, Messages, and managed Streaming services.
- Oversaw the team during its shift from traditional security reviews and operational approvals to AI assisted workflows. Areas that required operational approvals were transitioned to agent serviced workflows to speed up engineering velocity. Agents performed pre-review toil, such as identifying tasks and creating basic threat models to support human efforts.
- Developed agents to handle parts of manager responsibilities, such as giving feedback on various forms of writing such as self-evaluations, escalation emails, and team agendas. Created a guide that assisted engineers in understanding how to write Situation-Behavior-Impact (SBIs) statements, and developed an agent to give feedback on quality and missing elements.
- Maintained team effectiveness by actively engaging with workload management and shifting priorities based on launch schedules. Escalations and strong judgement played a role in navigating the correct level of visibility and decision making necessary to resolve conflict and disagreement. All product launches and features required security review which requires constant vigilance and rebalancing to align resources with customer needs.
- Introduced the team to common engineering practices like Asana for tracking project status and impact, structured 1on1s with documents, and maintaining action item lists with projected delivery estimates. Drove backlog burn downs and maintaining accurate metrics through targeted clean up efforts. Utilized GenAI to process and monitor work streams, identifying issues for correction.