Michael Scovetta

CEO

Middleburg, Virginia, United States24 yrs 8 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Expert in open source software supply chain security.
  • Led initiatives to improve cybersecurity practices.
  • Passionate about solving complex technical challenges.
Stackforce AI infers this person is a Cybersecurity expert with a focus on open source and enterprise security solutions.

Contact

Skills

Core Skills

Information SecurityOpen Source Security

Other Skills

Open-Source SoftwareStatic AnalysisProgram ManagementTechnological InnovationEnterprise ArchitectureCloud ComputingSecurityEnterprise SoftwareSoftware DevelopmentComputer SecurityApplication SecuritySaaSInformation TechnologyJavaIT Strategy

Experience

24 yrs 8 mos
Total Experience
3 yrs 6 mos
Average Tenure
12 yrs 8 mos
Current Experience

Microsoft

2 roles

Principal Security PM Manager

Promoted

Feb 2017Present · 9 yrs 3 mos

  • I lead a team that helps Microsoft use open source software safely. We conduct innovative research, create security tools, write white papers, evangelize good practices, and analyze software at scale to identify critical vulnerabilities and new types of malware.
  • I lead work within Open Source Security Foundation (openssf.org), where we are trying to improve the security of the open source ecosystem and the most influential parts of it, including the Alpha-Omega project (alpha-omega.dev) and the Identifying Security Threats working group.
  • I'm passionate about solving the hardest technical challenges, moving the needle from "zero to one". I'm hands on, straddling the intersection between software engineering, security, and open source. I'm lucky because I get to work with some of the smartest people on the planet equally passionate about their work and the future we envision.
Information SecurityOpen-Source SoftwareStatic AnalysisProgram ManagementOpen Source SecurityTechnological Innovation

Senior Security PM Manager

Sep 2013Feb 2017 · 3 yrs 5 mos

Cbs corporation

Director, Advanced Technology

Aug 2011Aug 2013 · 2 yrs · New York, NY

  • Responsible for the ideation and prototype implementation of next generation technologies related to mobile platforms, interactive television, and social media, including development of enterprise iOS apps to support television ratings analysis and distribution.

Ca technologies

Senior Architect, IT Security

Oct 2008Jul 2011 · 2 yrs 9 mos

  • My role as senior architect in CA's IT Security department has given me access to a wide array of projects and activities in the security space. Some of my more notable contributions are as follows:
  • Accepted to the Global Future Leaders Development Program
  • Responsible for Security Architecture within the Enterprise Architecture group
  • Co-led the development of a company-wide software security assurance program
  • Served on the "Council for Technical Excellence" (technical thought leadership organization)
  • Guided the "Engineering Excellence" committee on implementation of software security assurance program
  • Designed and presented an SSL certificate management solution to C-level executive management
  • Led security architecture within CA's internal IT area, supporting 500,000 customers and employees
  • Reviewed and re-architected the Identity & Access Management technology program
  • Launched the "Brown Bag Technical Sessions" program (internal "tech talks" and invention farming)
  • Represented CA at an industry review panel of NIST's "Supply Chain Risk Management" recommendation

Cigital

Senior Security Consultant

May 2008Oct 2008 · 5 mos

  • At Cigital, I was fortunate to work with some incredibly smart, talented folks, securing our customers' critical business assets. In my role as a Senior Security Consultant, I led a number of security assessments of high-profile web-based applications. These assessments included penetration testing, but were also focused on identifying and helping to mitigate business risk.
  • As part of a smaller project, I reverse engineered and wrote a brute-force password cracker for a full-disk encryption product. I also wrote a series of technical security standards for Java and .NET technologies, and performed remediation on some insecure C# and ASP.NET code.

Ubs financial services, inc.

Associate Director

Jun 2005May 2008 · 2 yrs 11 mos

  • Reported directly to the Chief Information Security Officer
  • Conducted targeted, in-depth risk assessments against enterprise systems and processes
  • Designed and developed static analysis tool (Yasca), leveraging FOSS components
  • Taught "Lunch & Learn" events on various topics related to information and application security
  • Evaluated commercial and FOSS black-box and static analysis security testing tools
  • Conducted dozens of penetration tests against applications and hardware components
  • Served as thought leader in areas of application security and cryptography
  • Advised architects and project implementation teams on matters of software security and secure design
  • Investigated security-related incidents (including forensics) and reported software vulnerabilities
  • Authored two chapters of OWASP's "A Guide to Building Secure Web Applications and Web Services"

Computer associates

Senior Application Developer

Jun 2002Jun 2005 · 3 yrs

  • Served as member of the Web-Services Expert Panel at J-Boss World 2005.
  • Contributed regularly to security mailing lists (including webappsec and bugtraq)
  • Served as subject matter expert for secure software development
  • Led the technical design of an enterprise-wide contract management system

Cornell university

Teaching Assistant

Jan 2001Dec 2001 · 11 mos

  • Taught students weekly at supplementary section
  • Conceived and implemented "Honors" section

Education

Cornell University

Master of Engineering - MEng — Computer Science

Jan 2001Dec 2001

Cornell University

M.Eng — Computer Science

Jan 2001Jan 2001

Hofstra University

B.S. — Computer Science & Mathematics

Jan 1997Jan 2000

St. Anthony's High School

NYS Regents — High School

Jan 1993Jan 1997

Stackforce found 100+ more professionals with Information Security & Open Source Security

Explore similar profiles based on matching skills and experience