Derek Samford

CEO

Austin, Texas, United States26 yrs 1 mo experience
Highly StableAI Enabled

Key Highlights

  • Over 26 years of experience in security and software engineering.
  • Expert in leading global multi-functional teams for secure software delivery.
  • Passionate about security talent development and diversity.
Stackforce AI infers this person is a Fintech security leader with extensive experience in product and infrastructure security.

Contact

Skills

Core Skills

Security OperationsProduct SecuritySecurity EngineeringApplication SecurityRisk ManagementGenerative AiProject Management

Other Skills

Infrastructure SecurityAI SecuritySecurity ArchitectureCross-functional Team LeadershipDevSecOpsKubernetesDevOpsDisaster RecoveryVirtualizationServersCitrixCloud ComputingNetwork SecurityFirewallsSecurity

About

As Deputy CISO at Marqeta, a cutting edge innovator in the FinTech space delivering embedded finance solutions, I am responsible for the vision, leadership, execution and strategy of Product, Infrastructure Security, and Security Operations and Response throughout the company. With over 26 years of experience in security, cloud, DevSecOps, and software engineering, I bring a unique empathy and perspective to collaborating with Engineering and IT on positive security outcomes. I live for large problems that require sophistication and simplicity, and I thrive on leading global multi-functional teams to design and deliver secure software. I have a strong passion for security talent development, and I balance hiring and training to ensure excellence and diversity in a tightly constrained cyber security job market. My mission is to enable Marqeta to scale and measure its product security and protect its customers and partners.

Experience

26 yrs 1 mo
Total Experience
2 yrs 5 mos
Average Tenure
1 yr 10 mos
Current Experience

Marqeta

2 roles

Deputy Chief Information Security Officer

Promoted

Mar 2026Present · 2 mos

  • Responsible for Product Security, Security Operations,Infrastructure Security, and AI Security. Intersects strongly with compliance and strategy to help ensure secure by design products and a cohesive, risk informed security roadmap.
Product SecuritySecurity OperationsInfrastructure SecurityAI Security

Vice President of Product and Infrastructure Security

Jul 2024Present · 1 yr 10 mos

  • Responsible for product security, security architecture, and security engineering functions
Product SecuritySecurity ArchitectureSecurity Engineering

Avalara

2 roles

Senior Director of Product Security

Promoted

Apr 2021Jul 2024 · 3 yrs 3 mos

  • Responsible for the inception, vision, application, leadership, and strategy of the Security Engineering department.
  • Drove inception and kick-off of Security Champions program, providing transparency and communication of security initiatives, as well as clear points of contact for the SIRT team
  • Core participant in Generative AI working group, responsible for general guidance on AI security and participated in the creation of generative AI policies, standards, and training
  • Drives charter and execution of Application Security and Adversarial teams
  • Dramatically expanded the Security Engineering team to meet industry standards for the number of applications and developers we were servicing.
  • Accountable for external security auditing, security testing, application security, responsible disclosures, CI/CD, internal security assessments, customer security consults, and red teaming
  • Aligns strategic security initiatives with business objectives and ensures adoption throughout engineering
  • Owns security training initiatives for Engineering
  • Organized gamified security exercises throughout Engineering
  • Drove comprehensive automated SDLC validations, including threat modeling, DAST, SAST, SCA with vulnerability aggregation and automated ticketing
  • Delivered holistic security dashboard and standardized security issue reporting
Risk ManagementGenerative AICross-functional Team LeadershipApplication SecurityDevSecOps

Director of Product Security

Jul 2019Apr 2021 · 1 yr 9 mos

  • Responsible for the inception, vision, application, leadership, and strategy of the Security Engineering department.
  • Drove inception and kick-off of Security Champions program, providing transparency and communication of security initiatives, as well as clear points of contact for the SIRT team
  • Drives charter and execution of Application Security and Adversarial teams
  • Dramatically expanded the Security Engineering team to meet industry standards for the number of applications and developers we were servicing.
  • Accountable for external security auditing, security testing, application security, responsible disclosures, CI/CD, internal security assessments, customer security consults, and red teaming
  • Aligns strategic security initiatives throughout engineering
  • Owns security training initiatives for Engineering
  • Drives gamified security exercises throughout Engineering
  • Drove comprehensive automated SDLC validations, including threat modeling, DAST, SAST, SCA with vulnerability aggregation and automated ticketing
  • Drove initiative for holistic security dashboard and standardized security issue reporting
KubernetesDevOpsDisaster RecoveryRisk ManagementProject Management

Mobileiron

2 roles

Manager, Security Engineering

Mar 2019Jul 2019 · 4 mos

  • Managing the DevSecOps team at MobileIron
DevOpsDisaster RecoveryRisk ManagementProject Management

Senior Staff Security Engineer

Jun 2017Mar 2019 · 1 yr 9 mos

  • Cloud Security Team Lead
  • Leads team of security engineers in efforts to provide security engineering guidance, incident response, and security design review across the MobileIron Cloud products
  • Review all customer facing product engineering services, perform threat modeling, and provide general recommendations to product development team.
  • Coordinates internal AWS account and application audits, ensuring a least permissive model across our network and access controls and assisting in moving to a modern deployment strategy.
  • Responsible for the initial development and implementation of a DevSecOps strategy to keep pace with Agile Development within mobile iron.
  • Drove and coordinated automation strategy across entire Product Security team
  • Lead technical response to FedRAMP auditors for Cloud and Application level controls tracking to NIST 800-53 standards
  • Finetuned and automated vulnerability scanning strategy, to allow for automated ticket creation and closure of production vulnerabilities utilizing Rapid7 Nexpose
  • Utilized business intelligence analytics tools and disparate datasets to create a unified Executive-consumable dashboard for Product Security
  • Responsible for configuration and troubleshooting of product development deployed Palo Alto IDS
Disaster RecoveryRisk ManagementProject Management

Citrix

2 roles

Principal Software Test Engineer

Mar 2016Jun 2017 · 1 yr 3 mos · Fort Lauderdale, FL

  • Release lead for WorxHome and MDX components of the XenMobile software suite.
  • Responsible for the creation, training, and planning of the Security Validation Team within XenMobile Engineering, responsible for ensuring a high security bar in every release.
  • Operated as interim Android dev manager, handling all operational decisions
  • Lead a team of 20+ engineers owning two products.
  • Coordinated with external pen-test groups to provide infrastructure and guidance
  • Played critical role in the organizations transition to an agile model.
  • Architected the QCKR system, an internal private cloud service to automate deployment of our product during development.
Disaster RecoveryRisk ManagementProject Management

Staff Software Test Engineer

Jan 2014Mar 2016 · 2 yrs 2 mos · Fort Lauderdale, FL

  • Test Design Lead for the WorxHome client in the XenMobile product group.
Disaster RecoveryRisk ManagementProject Management

Syncreticorp

Ceo And Founder

Aug 2013Dec 2013 · 4 mos · Fort Lauderdale, Florida

  • Cloud infrastructure consulting
Disaster RecoveryProject Management

Netapp

Field Support Engineer 4

Sep 2009Aug 2013 · 3 yrs 11 mos · Dallas, TX

  • Became the Subject Matter Expert in the FSE organization with regards to performance analysis, building off my strong performance testing background.
  • Developed and maintained excellent relationships with customers that were fostered during extremely trying cases.
  • Consulted for design advice, especially when performance was a strong consideration.
  • Developed very strong inter-departmental relationships, while being engaged to fulfill Professional Services duties, both in cases where both teams had responsibilities, as well as to fill gaps in PS resourcing.
  • Point of process and technical escalation for the local account teams, ensuring a high level of support for critical customers and hot cases.
Disaster RecoveryProject Management

Citrix systems

Lead Software Test Engineer

Jan 2005Sep 2009 · 4 yrs 8 mos · Fort Lauderdale, FL

  • Product Development (2007-2009)
  • Team lead, responsible for ensuring the quality, performance, and scalability for XenApp and related products through feature spec design, test plan creation and execution.
  • Designed and implemented core design and architecture of Project SkyNET, a project focused on utilizing cloud computing to allow dynamic provisioning of virtual machines for testers and automation. Resulted in a dramatically reduced the cost of deployment, increased server density, reduced deployment times, and increased engineer efficiency.
  • Delivered complete test plan rewrite for XenApp Presentation Server 5.0, utilizing a pair-wise methodology to increase efficiency and test coverage.
  • Test Release Lead on Presentation Server 4.5 HRP03. Led the test planning, feature specification review, and execution of an extensive and global cross departmental release. Published a whitepaper and webinar on the scope of changes in HRP03 with Dev Lead.
  • Delivered planning and contract criteria for the Active Directory integration feature, performing analysis of potential scalability and bottleneck issues and creating must-meet criteria for the 3rd party code base.
  • Life Cycle Maintenance (2005-2007)
  • Team Lead, coordinating the testing and release of Hotfix Rollup Packs. Performed and managed team execution of line item testing, documentation verification, stress testing, and package validation.
  • One of two core members in charge of the creation of a scalability test team for the Life Cycle Maintenance department.
  • Trained individuals to understand the complexities and requirements of large scale testing.
  • Core member of the Infrastructure team, delivering plans, implementing virtualization and SAN technologies that increased server density in the same space and allowed for more efficient power utilization.
Disaster Recovery

Net phone blue

Network Operations Manager

Jul 2002Jan 2005 · 2 yrs 6 mos

  • Network Operations Manager
  • Responsible for architecture and implementation of a VoIP platform from the ground up. Also ensured the day to day health and stability of the platform and underlying network architecture.
  • Designed and implemented wholesale VoIP network utilizing a combination of Cisco hardware, open-source Asterisk software, and third party billing software (SysMaster)
  • Worked with Digium and external contractors to make significant improvements to the Asterisk H.323 stack.
  • Designed and implemented a retail VoIP solution that was eventually sold to a third party.
Disaster Recovery

Tristar communications

Network Operations Manager

Jan 2002Jul 2002 · 6 mos

  • Brought in to oversee overall network redesign with redundancy and scalability in mind, implementing iBGP and OSPF in the previously static environment. This included a network wide upgrade of all core routers and switches, and utilized Riverstone hardware. Responsible for implementation and configuration of all client related services. (I.E. Qmail, Apache, client bandwidth monitoring.) Responsible for implementation and configuration of all network related services. Responsible for IP address management and overall handling of abuse complaints.
Disaster Recovery

Sands river wireless

Network Operations Manager

Feb 2001Jan 2002 · 11 mos · Miami, FL

  • Network Operations Manager
  • Managed the Network Operations Center and coordinated the efforts of the Field Support team.
  • Designed and implemented a total network overhaul increasing the capacity, redundancy, and scalability of the entire network.
Disaster Recovery

Fuzion wireless

Network Operations Manager

Mar 2000Feb 2001 · 11 mos · Boca Raton, FL

  • Fuzion Wireless, Boca Raton, Fl 2000 - 2001
  • Internet Service Provider
  • Network Operations Manager
  • Managed and coordinated staff of 12 network engineers. Responsible for overall health and maintenance of the network.
  • Created a home-grown VPN that could be flexibly and dynamically scaled out using a combination of Linux, FreeS/WAN, and TCL.
  • Performed a full security audit of the entire network revealing numerous penetrations. Subsequently ensured a full hardening of the entire network, with no further known security compromises.
  • Designed and architected a network overhaul, implementing Cisco, BGP, and OSPF for redundancy.
Disaster Recovery

Education

Florida Atlantic University

N/A — Computer Science

Jan 2000Jan 2001

Stackforce found 100+ more professionals with Security Operations & Product Security

Explore similar profiles based on matching skills and experience