Charlotte T.

DevOps Engineer

United States18 yrs 9 mos experience
AI EnabledAI ML Practitioner

Key Highlights

  • Over 15 years of experience in application security.
  • Built scalable security workflows at Coinbase.
  • Developed open source compliance platform, CharlottesWeb.
Stackforce AI infers this person is a Cloud Security and Application Security expert with a focus on AI integration.

Contact

Skills

Core Skills

Application SecurityThreat ModelingCloud SecuritySecure ArchitectureBlockchain SecurityDevsecopsIdentity ManagementWeb SecurityPenetration TestingSoftware DevelopmentTechnical Writing

Other Skills

CI/CD GuardrailsVulnerability TriageAI Risk EvaluationSecure ArchitecturesIAM ModelsNetwork SegmentationCI/CD Security ControlsSecurity ReviewsVulnerability Risk ScoringIAM PoliciesAutomationSAST AutomationCI/CD WorkflowsIdentity SystemsAuthentication Architecture

About

Security is a design problem, not a scanning problem. I have spent 15+ years proving that by embedding security directly into how teams build software, from threat modeling and secure architecture to CI/CD guardrails and automated compliance. I have led security at AWS, Coinbase, PwC, and Daimler, partnering with engineering teams to secure SaaS platforms, cloud infrastructure, APIs, authentication systems, and blockchain networks. At Coinbase I built workflows that scaled to 120+ security reviews per quarter. At AWS I designed secure architectures for enterprise customers in regulated environments. Most recently I built CharlottesWeb, an open source compliance platform that maps security controls across HIPAA, NIST 800-53, GDPR, SOX, FedRAMP, and other frameworks, so teams can map once and comply many. It has been cloned by 260+ developers in its first two weeks. I am currently focused on the intersection of application security and AI, including LLM security risks like prompt injection and model data leakage, and building developer focused security tooling that helps teams ship safely at speed.

Experience

18 yrs 9 mos
Total Experience
2 yrs
Average Tenure
--
Current Experience

Appfolio

Manager, Application Security

Jan 2025Feb 2026 · 1 yr 1 mo · Remote

  • Led application security strategy for a large SaaS platform, embedding security into engineering workflows through threat modeling, secure design reviews, and CI/CD guardrails. Oversaw vulnerability triage and validation across SAST, DAST, and SCA while partnering with product teams to prioritize and remediate issues. Evaluated emerging risks in AI systems, including prompt injection and model data leakage.
Application SecurityThreat ModelingCI/CD GuardrailsVulnerability TriageAI Risk Evaluation

Amazon web services (aws)

Senior Security and Privacy Engineer

Oct 2022Dec 2024 · 2 yrs 2 mos

  • Designed and reviewed secure architectures for cloud-native SaaS systems in AWS. Implemented IAM models, network segmentation, and CI/CD security controls to enforce least privilege and secure deployments. Guided engineering teams on secrets management, logging, and cloud security best practices in regulated environments.
Secure ArchitecturesIAM ModelsNetwork SegmentationCI/CD Security ControlsCloud SecuritySecure Architecture

Coinbase

Senior Manager, Blockchain Security

Oct 2021Aug 2022 · 10 mos

  • Led threat modeling and security reviews for blockchain infrastructure and smart contract systems. Built scalable security assessment workflows supporting 120+ security reviews per quarter and improved vulnerability risk scoring and remediation tracking. Participated in incident response for platform and distributed node security events.
Threat ModelingSecurity ReviewsVulnerability Risk ScoringBlockchain Security

Amazon web services (aws)

Senior Security Consultant

May 2021Sep 2021 · 4 mos

  • Partnered directly with enterprise customers to design and secure cloud-native architectures in AWS. Helped organizations deploying to the cloud implement IAM policies, SCPs, Config rules, and network segmentation to enforce least privilege and governance. Built automation using Lambda and API Gateway to support security operations and incident response while advising engineering teams on logging, secrets management, and secure deployment practices.
Cloud SecurityIAM PoliciesNetwork SegmentationAutomationSecure Architecture

Pwc

Senior Manager Application Security

Jun 2017Oct 2019 · 2 yrs 4 mos

  • Built DevSecOps programs that integrated security into modern development pipelines. Implemented SAST automation, secure CI/CD workflows, and developer-focused security standards. Led vulnerability management initiatives and introduced modern TLS and secure automation for artifact storage and secrets management.
DevSecOpsSAST AutomationCI/CD WorkflowsApplication Security

Daimler trucks north america

Web Security Infrastructure Lead - IAM

Aug 2015Jun 2017 · 1 yr 10 mos

  • Led a 24/7 security engineering team responsible for identity systems including SSO and federation. Strengthened authentication architecture through monitoring, least privilege, and improved session controls. Served as incident commander for high-severity infrastructure and authentication incidents.
Identity SystemsAuthentication ArchitectureIncident CommandIdentity ManagementWeb Security

Hewlett packard enterprise

Java Developer and Senior Information Security Consultant

Mar 2008Aug 2015 · 7 yrs 5 mos

  • Performed manual code review, penetration testing, and secure architecture assessments for enterprise systems. Delivered threat modeling, remediation planning, and security controls aligned with standards including ISO 27001, NIST, PCI, and HIPAA. Partnered with engineering teams to improve secure development practices.
Code ReviewPenetration TestingSecure Architecture AssessmentsApplication Security

Intel corporation

Programmer/Writer

Feb 2006Jan 2007 · 11 mos

  • Developed secure C++, Java, and PHP applications while supporting architecture, testing, and documentation for enterprise systems. Built internal tooling and SDK demonstrations while helping teams establish secure coding practices.
Secure ApplicationsArchitecture SupportDocumentationSoftware DevelopmentTechnical Writing

Cascade insights - b2b market research & marketing services

C# and Technical Content Developer

Dec 2003Dec 2004 · 1 yr

  • Designed and built mapping service clients using early WS-Security implementations to enable secure integration with Microsoft APIs. Developed video training modules and technical guidance to help developers understand and implement these APIs effectively. Supported engineering teams building secure integrations through documentation, demos, and developer education.
Mapping Service ClientsVideo Training ModulesTechnical Guidance

Veolia australia and new zealand

Technical Content Developer and Trainer

Jul 2000May 2002 · 1 yr 10 mos

  • Designed and delivered a training program for software engineers building product integrations with a CRM platform. Traveled internationally to teach the course and train additional instructors, scaling the program across global engineering teams. Partnered with product and engineering leadership to influence key product decisions that improved developer experience and supported real-world customer integration use cases.
Training Program DesignProduct Integrations

Education

University of Washington

Certified .NET Programmer

University of Puget Sound

Master of Arts - MA

University of Puget Sound

Bachelor of Arts - BA

Stackforce found 100+ more professionals with Application Security & Threat Modeling

Explore similar profiles based on matching skills and experience