
Stephen Putiyon
@stephenputiyon
Senior Product Security Engineer at Flexport securing LLM-powered logistics and agentic workflows with policy controls and security automation.
What I'm looking for
At Flexport, I designed threat models for LLM-powered shipment support and agentic operations, then built policy enforcement for agent tool calls and security automation across development and deployment workflows. I also implemented tenant-aware retrieval access controls and optimized AI workload container admission checks, reducing average review time from 45 minutes to 12 minutes.
At Palo Alto Networks, I developed Python tooling to test AI model endpoints and introduced threat-model checkpoints and reusable controls that reduced high-risk AI findings by 41%. Earlier, at Qualtrics, I reduced recurring cloud misconfiguration findings by 36%, and at Adobe I created reusable assessment scripts that cut manual evidence preparation by 28%.
Experience
Work history, roles, and key accomplishments
Designed threat models for LLM-powered shipment support and agentic operations, tracing prompt injection, excessive agency, data leakage, and unsafe tool execution to root causes. Built policy enforcement for agent tool calls using service identity, schema validation, authorization checks, and human approval gates before sensitive logistics actions.
Designed secure reference architectures for LLM-integrated security services, covering tenant isolation, secrets handling, tool permissions, logging, and failure containment. Implemented policy-as-code controls for Kubernetes workloads, image provenance, network boundaries, and workload identities across AWS and Azure environments.
Designed threat models for service APIs and data pipelines, identifying trust boundaries, authorization failures, injection paths, and tenant isolation risks. Implemented AWS controls for IAM, private networking, encryption, logging, and Kubernetes workloads supporting customer analytics and workflow services.
Implemented Java and Python utilities for API assessment, test data preparation, evidence collection, and repeatable validation of common application weaknesses. Developed unit and integration tests for security checks covering authentication, authorization, input validation, and session handling in web services.
Education
Degrees, certifications, and relevant coursework
George Mason University
Bachelor of Science, Information Technology
Bachelor of Science in Information Technology completed in December 2016.
Amazon Web Services
AWS Certified Security - Specialty, Cloud Security
AWS Certified Security - Specialty certification.
ISC2
Certified Cloud Security Professional, Cloud Security
Certified Cloud Security Professional certification.
Availability
Location
Authorized to work in
Salary expectations
Social media
Interested in hiring Stephen?
You can contact Stephen and 90k+ other talented remote workers on Himalayas.
Message StephenGet matched with your dream remote job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
