Embed, resell, or white-label AI security — OEM, scanner, MSSP, consulting, and reseller tracks are open now
LinkedIn adapter
Compact, public-safe proof text for profile featured items and share cards.
Canonical copy
Splunk Product Security Program Buildout Building a scalable, evidence-driven product security function for a global enterprise software platform. Partnered with Splunk to build and scale the product security program, strengthen secure development practices, and create the evidence, process, and organizational alignment needed to support a global software platform and enterprise customer expectations. Helped build Splunk's secure SDLC maturity by translating product-security goals into repeatable engineering practices: SAST/DAST workflows, app certification criteria, vulnerability triage, remediation prioritization, security scorecards, customer-trust evidence, and BSIMM/SAMM-style maturity framing across products and marketplace applications. Helped unblock enterprise customer trust by improving Splunk's product-security evidence, AppSec remediation posture, Veracode results, and secure SDLC maturity narrative. The work translated technical security improvements into customer-facing proof that supported a major enterprise deal and strengthened Splunk's broader product-security credibility. Transformed product security into a strategic, measurable, and trusted function.
Public-safe caveat
This case study uses conservative public-safe language. Specific internal metrics, program details, team structures, customer names, internal artifacts, and confidential information have been generalized or omitted. This case study uses conservative public-safe language based on uploaded resume/profile/project context and prior portfolio source material. Exact internal scorecards, vulnerability records, product-specific findings, customer identities, proprietary review criteria, and non-public remediation details are omitted. This case study uses conservative public-safe language based on uploaded resume/profile/project context and prior portfolio source material. Exact customer identity, deal value, Veracode report details, private findings, remediation tickets, internal communications, and proprietary security artifacts are omitted.