Peter Chestna

CEO

Boston, MA, USA34 yrs 11 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Led a company-defining platform transformation.
  • Transformed a large enterprise application security organization.
  • Served as senior advisor to enterprise customers.
Stackforce AI infers this person is a SaaS and Application Security expert with extensive leadership experience.

Contact

Skills

Core Skills

Advisory & ConsultingDevsecopsApplication SecurityProduct Adoption And RetentionExecutive LeadershipCustomer ExperienceProduct StrategySoftware Engineering

Other Skills

Market PositioningEnterprise AdoptionCustomer OutcomesRisk ManagementEngineering RequirementsArchitectural TransformationAgile MethodologiesDevOpsCustomer EngagementPolicy ManagementReportingC++LinuxDistributed SystemsJava

About

TL;DR: I help organizations turn complex engineering and application security challenges into clear priorities, durable platforms, and measurable outcomes. I’m an executive product, engineering, and application security leader with 20+ years of experience operating at the intersection of how software is built, how risk is managed, and how technology creates real-world business outcomes. My career spans hands-on engineering, engineering leadership, enterprise application security, and customer-facing executive roles. I’ve worked on both sides of the market—as an enterprise buyer and as a security product leader—which gives me a grounded perspective on what actually works in practice versus what sounds good in theory. I’m most effective in complex, high-friction environments where clarity, prioritization, and trust are essential. I specialize in translating technical complexity and risk into clear, defensible, outcome-driven priorities that teams can execute against—whether shaping product and platform direction, stabilizing organizations under stress, or guiding customers through difficult inflection points. Highlights from my work include: Leading a company-defining platform transformation that halted all other development, resulted in a patented innovation, and permanently shifted market positioning Turning around a large enterprise application security organization securing ~2,000 critical applications in a highly regulated environment Serving as Field CTO / Field CISO and senior advisor to enterprise customers, supporting adoption, retention, and growth Driving engineering and delivery transformations (Waterfall → Agile → DevOps → Kanban) that dramatically improved speed, predictability, and customer satisfaction I’m particularly interested in roles where product judgment, engineering execution, and customer reality must align—including VP Engineering, VP Cybersecurity, and CPO-adjacent leadership roles in application security, developer tooling, and infrastructure platforms. If you’re building, scaling, or rethinking a product or organization in this space, I’m always open to thoughtful conversations.

Experience

34 yrs 11 mos
Total Experience
5 yrs 5 mos
Average Tenure
8 yrs 8 mos
Current Experience

Checkmarx

CISO of North America/AppSec Practitioner in Residence

Jul 2021Feb 2026 · 4 yrs 7 mos

  • Executive-facing AppSec leader working at the intersection of product strategy, customer outcomes, and go-to-market execution.
  • Partnered with enterprise customers and prospects to shape application security programs, preserve renewals, and identify expansion opportunities.
  • Helped define and operationalize Checkmarx’s Find, Fix, Prevent narrative, contributing to sales enablement, SKO keynotes, and field messaging adopted broadly by the sales organization.
  • Led customer turnarounds by diagnosing maturity gaps, uncovering product usage friction, and guiding outcome-driven remediation plans.
  • Authored a practical product usage anti-patterns and maturity guidance framework, used by both customers and Customer Success teams to elevate conversations from tool operation to executive-level AppSec decision-making.
  • Provided field-informed input to product teams based on real-world customer behavior, adoption challenges, and enterprise constraints.
Application SecurityProduct StrategyCustomer OutcomesProduct Adoption and Retention

Bmo financial group

Enterprise Head of Application Security

Mar 2019Jul 2021 · 2 yrs 4 mos

  • Senior cyber leader responsible for application security outcomes across a highly regulated global financial institution.
  • Led a ~65-person organization securing approximately 2,000 of the bank’s most critical applications across multiple business lines.
  • Stabilized a function in crisis, transforming it into a low-friction, high-performing organization with strong internal trust, predictable execution, and a clear succession plan.
  • Owned the translation of security standards into actionable engineering requirements and adjudication of outcomes for Change Advisory Board (CAB) approval.
  • Designed and implemented a defensible, repeatable exception management process, improving risk clarity and reducing exception volume over time.
  • Championed automation to remove humans from low-value, error-prone work, enabling faster and more consistent guidance for engineering teams.
  • Created a net-new threat modeling function focused on real change and real risk, rather than static standards.
Application SecurityRisk ManagementEngineering RequirementsExecutive Leadership

Multiple organizations

Advisory Board Member | Investor | Contributing Editor

Sep 2017Present · 8 yrs 8 mos

  • Serve as an advisor and board member to early- and growth-stage application security and developer tooling companies, providing guidance on product strategy, market positioning, and enterprise adoption.
  • Advise founders and leadership teams on scaling security products, navigating regulated enterprise environments, and aligning engineering execution with customer and market realities.
  • Actively engaged as an angel investor in the application security ecosystem.
  • Contributing editor to industry publications including DevOps.com and SecurityBoulevard, writing on application security, DevSecOps, and software delivery.
  • Regular speaker and program committee contributor for industry conferences and communities, including SecureWorld, DevSecCon, and DevNetwork.
Product StrategyMarket PositioningEnterprise AdoptionAdvisory & ConsultingDevSecOps

Veracode

3 roles

Field CTO/Director of Developer Engagement

Mar 2016Mar 2019 · 3 yrs · Burlington, MA

  • As Field CTO, served as the face and voice of Veracode through international conference talks, webinars, interviews, and executive briefings.
Customer ExperienceDevSecOps

Director, Platform Engineering

Promoted

Aug 2011Mar 2016 · 4 yrs 7 mos · Burlington, MA

  • Conceived, pressure-tested, and led the largest architectural transformation in Veracode’s history, persuading leadership to halt all other development and delivering a patented platform innovation that became a long-term market differentiator.
  • Led engineering transformations from Waterfall → Agile → DevOps → Kanban, shrinking delivery cycles from months to days and dramatically improving predictability and responsiveness.
  • Led Project Purina, using Veracode to secure its own product—creating a repeatable, real-world AppSec implementation template that powered customer and prospect conversations and delivered the platform’s first customer-facing integrations.
  • Frequently engaged with Veracode’s largest and most operationally challenged enterprise customers to diagnose complex issues, provide root-cause clarity, and reframe isolated failures within overall program outcomes.
Architectural TransformationAgile MethodologiesDevOpsProduct StrategyDevSecOps

Principal Software Engineer

Aug 2006Aug 2011 · 5 yrs · Burlington, MA

  • I joined Veracode in 2006 as a platform developer and was instrumental in delivering the first version of Veracode’s service to customers. I built key aspects of the Veracode service including policy management and reporting that are still cornerstones of the value to customers.
Policy ManagementReportingSoftware EngineeringApplication Security

Ab initio

Consulting Engineer

Jul 2004Aug 2006 · 2 yrs 1 mo

Highground systems

Consulting Engineer

Feb 1996Jul 2004 · 8 yrs 5 mos

  • Acquired by Sun Microsystems in April 2001.

Flashpoint

Sr. Software Engineer

Feb 1994Feb 1996 · 2 yrs

Sytron

Software Engineer

Jun 1991Feb 1994 · 2 yrs 8 mos

Education

Worcester Polytechnic Institute

B.S. — Computer Science

Jan 1987Jan 1991

Stackforce found 100+ more professionals with Advisory & Consulting & Devsecops

Explore similar profiles based on matching skills and experience