At OpenGov, I lead application security initiatives and a team of application security engineers working to secure GovTech platforms. I deployed GitHub Dependabot and Renovate to detect vulnerable dependencies and automate patching pull requests.
I also led the HCM application’s security assessment and certification, from architecture and design review through penetration testing and security sign-off. I’ve embedded automated scanning, policy enforcement, and security gates into CI/CD pipelines, and supported SOC2/GovRamp certification audits.
Previously, at Cerillion Technologies, I implemented software composition analysis with Syft and Grype to generate SBOMs and scan build artifacts and container images. My work across application security, vulnerability remediation, and secure SDLC spans GovTech, cloud platforms, and enterprise applications.

