M

Marc E.

CTO

Austin, Texas, United States26 yrs 10 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Proven record in reducing enterprise security risk.
  • Expert in transforming Secure Software Development Lifecycle.
  • Innovative leader in automated security reviews.
Stackforce AI infers this person is a Security Architect specializing in Application Security for technology enterprises.

Contact

Skills

Core Skills

Application SecuritySecurity ManagementSecurity ArchitectureSecurity EngineeringThreat IntelligenceSecurity Research

Other Skills

Threat ModelingSecurity TestingSecurity ReviewProcess AutomationSecurity TrainingSecurity ReviewsSecure ArchitectureIncident ResponseSecurity Best PracticesSecurity StrategyRisk ManagementVulnerability AssessmentSecurity OperationsMalware DetectionSecurity Feed Management

About

Leader with a proven record of reducing enterprise security risk across top technology companies and successful startups. I lead strategic initiatives focused on transforming and scaling the Secure Software Development Lifecycle. I have demonstrated this through invention and innovation, process automation, and finding new frictionless ways of embedding secure defaults into developer workflows to achieve near-zero time-in-production for security issues while reducing the overall cost of security.

Experience

Amazon

2 roles

Head of Application Security

Promoted

Aug 2025Present · 7 mos · Austin, Texas Metropolitan Area · On-site

  • Drives Application Security across Amazon's diverse business portfolio, supporting 15 CISOs and Heads of Security in areas like healthcare, satellite launches, physical stores, and media and entertainment. The role provides crucial security review capacity (threat modeling, architecture review, security testing, validation, and launch readiness) and tailors centralized security offerings to meet the unique needs of each business unit.
  • Heads an organization chartered with reducing Amazon's security risk by innovating through automated security reviews. Our focus is scaling application security to meet unprecedented demand and backlog, ensuring security experts concentrate on bespoke, high-risk security issues and provide minimally disruptive security review services that delight builders.
  • Leads specialized Application Security teams, such as Mobile Security, that embed secure defaults into developer workflows, minimizing security time-to-fix and reducing the overall cost of security.
  • Oversee Amazon's Application Security Developer Engagement program, which provides essential security knowledge, guidance, and resources to builders and partners. This includes the Security Certifiers program, our solution for scaling the human tasks needed today in application reviews, and Security Training and Education, which provides frontline builder support services,
Application SecurityThreat ModelingSecurity TestingSecurity ReviewProcess AutomationSecurity Management

Head of Security, Games, Media and Entertainment Security

May 2020Jul 2025 · 5 yrs 2 mos · Austin, Texas Metropolitan Area · On-site

  • Led eight security teams, Amazon MGM Studios, Digital Acceleration, Games Studios, Luna, Music, Prime Gaming, Prime Video, and Wondery. We obsess over the security of our customers experience and end-to-end security of our content suppliers. This includes making sure the data our customers provide to us is protected, and that the data we provide to our customers is also protected. We analyze, asses, solution and recommend security solutions to give our customers the best experience possible, without putting them or us at risk.
  • We protect customers and their data by performing security reviews of applications, providing guidance on secure architecture designs, and helping development teams make informed risk decisions. We enable business innovation by partnering directly with engineers to implement security best practices and scale our impact through security campaigns and automated tooling requirements. Through proactive application security measures and incident response, we ensure all client and cloud applications maintain a strong security posture while delivering exceptional customer experiences.
Security ReviewsSecure ArchitectureIncident ResponseSecurity Best PracticesApplication SecuritySecurity Management

Fastly

Head of Security

Oct 2017May 2020 · 2 yrs 7 mos · San Francisco Bay Area · Remote

  • Established and Leads Fastly's Security Architecture Group, which is focused on Security Strategy, Security Risk Management, Secure Software Development Lifecycle and Training initiatives.
  • Established and Leads Fastly's Discovery, Detection and Response Team, responsible for Security Operations, Vulnerability Assessment and Offensive Security program.
  • Established and Leads Fastly's Security Orchestration Team, who implements Security Analytics and Alerting, Security Telemetry Systems, Compliance Tools and deployment of all security tools into developer workflows and processes.
Security StrategyRisk ManagementVulnerability AssessmentSecurity OperationsSecurity ManagementSecurity Architecture

Arbor networks, the security division of netscout

Sr. Manager, Arbor Security Engineering and Response Team (ASERT)

Sep 2012Oct 2017 · 5 yrs 1 mo · Ann Arbor, Michigan, United States · On-site

  • Managed key relationships with Global Tier 1 service providers, large enterprises, governments and their respective CERT organizations. Gave tailored presentations showing relation to the global security landscape, providing time-based comparison across industry vertical, geography, and risk profile. Managed external data sharing relationships.
  • Introduced new product line detection capabilities in the form of a malware-focused reputation feed. Managed all aspects of the security feed content pipeline, including security researchers and supporting development resources. Modernized legacy malware processing infrastructure.
  • Expanded team to include a Threat Intelligence capability, responsible of turning indicators into higher-order narratives, through publishing timely blogs and threat briefs. I was point of contact for press, analysts, conference speaking engagements on a wide variety of security topics.
Threat IntelligenceMalware DetectionSecurity Feed ManagementSecurity Engineering

Hewlett packard enterprise

2 roles

Distinguished Technologist

Dec 2010Sep 2012 · 1 yr 9 mos · On-site

  • Research in the areas of botnet detection via machine learning, host reputation using marginal belief propagation, DDoS, collaborative security and dynamic instrumentation for malware.
Botnet DetectionMachine LearningDynamic InstrumentationSecurity Research

Principal Security Researcher - TippingPoint

Feb 2006Dec 2010 · 4 yrs 10 mos · On-site

  • Analyzed vulnerabilities, exploits, applications, protocols, and developed proof-of-concept code, both with the Digital Vaccine Team and Zero Day Initiative.
Vulnerability AnalysisExploit DevelopmentSecurity Research

L3 technologies

Sr. Security Engineer

May 1999Feb 2006 · 6 yrs 9 mos · Waco, Texas · On-site

  • Vulnerability Research and Exploit Analysis
Vulnerability ResearchExploit Analysis

Education

Columbia University

Master’s Degree — Computer Science

Jan 2002Jan 2006

Baylor University

Bachelor’s Degree

Jan 1997Jan 2001

Stackforce found 100+ more professionals with Application Security & Security Management

Explore similar profiles based on matching skills and experience