Craig Bartoshesky
@craigbartoshesky
Cybersecurity leader specializing in AppSec, Secure SDLC, and DevSecOps with measurable risk reduction.
What I'm looking for
I am a cybersecurity leader with 15+ years driving enterprise Application Security, Secure SDLC, and vulnerability management programs across Fortune 10–500 organizations. I translate complex security posture into clear business impact and advise executive stakeholders on scalable AppSec and DevSecOps capabilities.
I have led AppSec delivery across large application portfolios, operationalized repeatable security frameworks, and reduced late-stage findings and recurring vulnerabilities by meaningful percentages. I’ve built threat modeling playbooks, managed penetration testing and tooling rollouts (SAST, DAST, SCA, ASPM), and contributed to AI-assisted testing and automation pilots.
I mentor and grow teams, support client delivery and account expansion, and align security strategy with engineering execution to accelerate secure product delivery in regulated and high-stakes environments.
Experience
Work history, roles, and key accomplishments
Managed high-visibility AppSec engagements and led secure SDLC and DevSecOps delivery, reducing late-stage findings by ~25–35% and accelerating assessment ramp-up by ~20–30%.
Led AppSec delivery across 15–30+ applications annually, embedding threat modeling, penetration testing, and secure code review to cut assessment ramp-up time ~20–30% and reduce recurring findings ~20–30%.
Application Security Engineer
Aspect Security
Jan 2017 - Jan 2018 (1 year)
Performed web and API penetration tests and code reviews as technical lead for financial clients, scoped engagements, and acted as client interface for vulnerability management initiatives.
Coordinated security architecture reviews, penetration testing, and secure code review across vendor teams, strengthening secure SDLC adoption and reducing recurring vulnerabilities.
Delivered UI modernization and application enhancements across multiple Agile projects, maintained key applications, and supported major launches to improve reliability and on-time delivery.
Education
Degrees, certifications, and relevant coursework
The Pennsylvania State University
Bachelor of Information Sciences and Technology, Information Sciences and Technology
Bachelor of Information Sciences and Technology from The Pennsylvania State University.
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring Craig?
You can contact Craig and 90k+ other talented remote workers on Himalayas.
Message CraigFind your dream job
Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!
