Embed, resell, or white-label AI security — OEM, scanner, MSSP, consulting, and reseller tracks are open now
A.Team adapter
Outcome-oriented proof text for project entries and profile summaries.
Canonical copy
Head of Product Security Splunk Partnered with Splunk to build and scale the product security program, strengthen secure development practices, and create the evidence, process, and organizational alignment needed to support a global software platform and enterprise customer expectations. Helped build Splunk's secure SDLC maturity by translating product-security goals into repeatable engineering practices: SAST/DAST workflows, app certification criteria, vulnerability triage, remediation prioritization, security scorecards, customer-trust evidence, and BSIMM/SAMM-style maturity framing across products and marketplace applications. Helped unblock enterprise customer trust by improving Splunk's product-security evidence, AppSec remediation posture, Veracode results, and secure SDLC maturity narrative. The work translated technical security improvements into customer-facing proof that supported a major enterprise deal and strengthened Splunk's broader product-security credibility. 70%+ directional reduction in high and critical findings over time.
Public-safe caveat
This case study uses conservative public-safe language. Specific internal metrics, program details, team structures, customer names, internal artifacts, and confidential information have been generalized or omitted. This case study uses conservative public-safe language based on uploaded resume/profile/project context and prior portfolio source material. Exact internal scorecards, vulnerability records, product-specific findings, customer identities, proprietary review criteria, and non-public remediation details are omitted. This case study uses conservative public-safe language based on uploaded resume/profile/project context and prior portfolio source material. Exact customer identity, deal value, Veracode report details, private findings, remediation tickets, internal communications, and proprietary security artifacts are omitted.