Skip to main content
Stephen PutiyonSP
Open to opportunities

Stephen Putiyon

@stephenputiyon

Senior Product Security Engineer at Flexport securing LLM-powered logistics and agentic workflows with policy controls and security automation.

United States
Message

What I'm looking for

I’m looking to secure AI and agentic products by turning emerging attack paths into practical controls, resilient products, and informed decisions.

At Flexport, I designed threat models for LLM-powered shipment support and agentic operations, then built policy enforcement for agent tool calls and security automation across development and deployment workflows. I also implemented tenant-aware retrieval access controls and optimized AI workload container admission checks, reducing average review time from 45 minutes to 12 minutes.

At Palo Alto Networks, I developed Python tooling to test AI model endpoints and introduced threat-model checkpoints and reusable controls that reduced high-risk AI findings by 41%. Earlier, at Qualtrics, I reduced recurring cloud misconfiguration findings by 36%, and at Adobe I created reusable assessment scripts that cut manual evidence preparation by 28%.

Experience

Work history, roles, and key accomplishments

Flexport logoFL
Current

Senior Product Security Engineer

Jan 2024 - Present (2 years 9 months)

Designed threat models for LLM-powered shipment support and agentic operations, tracing prompt injection, excessive agency, data leakage, and unsafe tool execution to root causes. Built policy enforcement for agent tool calls using service identity, schema validation, authorization checks, and human approval gates before sensitive logistics actions.

Palo Alto Networks logoPN

Product Security Engineer, AI Platforms

Jul 2021 - Dec 2023 (2 years 5 months)

Designed secure reference architectures for LLM-integrated security services, covering tenant isolation, secrets handling, tool permissions, logging, and failure containment. Implemented policy-as-code controls for Kubernetes workloads, image provenance, network boundaries, and workload identities across AWS and Azure environments.

Qualtrics logoQU

Cloud Security Engineer

Jan 2019 - Jun 2021 (2 years 5 months)

Designed threat models for service APIs and data pipelines, identifying trust boundaries, authorization failures, injection paths, and tenant isolation risks. Implemented AWS controls for IAM, private networking, encryption, logging, and Kubernetes workloads supporting customer analytics and workflow services.

Adobe logoAD

Software Security Analyst

Jan 2017 - Dec 2018 (1 year 11 months)

Implemented Java and Python utilities for API assessment, test data preparation, evidence collection, and repeatable validation of common application weaknesses. Developed unit and integration tests for security checks covering authentication, authorization, input validation, and session handling in web services.

Education

Degrees, certifications, and relevant coursework

George Mason University logoGU

George Mason University

Bachelor of Science, Information Technology

Bachelor of Science in Information Technology completed in December 2016.

Amazon Web Services logoAS

Amazon Web Services

AWS Certified Security - Specialty, Cloud Security

AWS Certified Security - Specialty certification.

ISC2 logoIS

ISC2

Certified Cloud Security Professional, Cloud Security

Certified Cloud Security Professional certification.

Tech stack

Software and tools used professionally

Get matched with your dream remote job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan