Skip to main content
MM
Open to opportunities

Marcus Morris

@marcusmorris1

I harden software supply chains, CI/CD pipelines, secrets, Linux systems, and enterprise applications.

Zimbabwe
Message

I've secured browser extensions, Google Workspace applications, enterprise endpoints, and API gateways at Flashpoint, completing 70+ application assessments and reviewing 100+ third-party vendors. I automated extension analysis with Python and Semgrep, administered Cloudflare WAF, and implemented Prisma SASE DLP policies to reduce application and data-exfiltration risk.

I'm currently researching software supply chain risks through self-hosted Forgejo Actions, OpenSSF Scorecard, Syft, Grype, and SLSA controls. Previously, I built self-healing Tripwire automation at Mastercard, reduced manual remediation by 50%, and engineered Chef and Jenkins migrations supporting zero-touch deployments across thousands of agents.

Experience

Work history, roles, and key accomplishments

CE
Current

Security Researcher

Ceaz

Jan 2026 - Present (8 months)

Conducted vulnerability and supply chain research, integrating tools like OpenSSF Scorecard, Syft, and Grype to identify risks. Contributed to open-source projects and performed web application evaluations.

Education

Degrees, certifications, and relevant coursework

HS

High School

High School Diploma, General Studies

Completed high school education in June 2011.

Get matched with your dream remote job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan