Shiloh Heurich

DevOps Manager

San Francisco, California, United States22 yrs 7 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Co-founded a publicly trusted Certification Authority.
  • Expert in architecting internet-scale security systems.
  • Proven track record in cryptographic solutions and identity management.
Stackforce AI infers this person is a Cybersecurity Architect with extensive experience in cryptographic systems and identity management.

Contact

Skills

Core Skills

Cloud SecurityPki

Other Skills

Private Key ManagementCryptographyGo (Programming Language)Python (Programming Language)SQLPHPImplementing robust cryptographic solutions and key material managementDeveloping mission-critical authentication and authorization systemsLeading cross-functional teams to deliver complex security projectsArchitecting and scaling internet-scale security systems from concept to productionDistributed SystemsFederated Identity ManagementNetwork SecuritySolarisSystem Architecture

About

Security engineer with 10+ years of experience in cryptographic security, system architecture, and key material management. Co-founded a publicly trusted Certification Authority (CA), recognized by major tech companies and integrated into global root stores. Skilled at taking greenfield projects to production, from initial concept to fully operational systems, while ensuring robust architecture, scalability, and security. Proven expertise in internet-scale architecture and engineering, delivering mission-critical solutions across commercial and government organizations with a focus on authentication, authorization, and identity management. Expertise in: - Architecting and scaling internet-scale security systems from concept to production - Implementing robust cryptographic solutions and key material management - Developing mission-critical authentication and authorization systems - Leading cross-functional teams to deliver complex security projects

Experience

22 yrs 7 mos
Total Experience
2 yrs 6 mos
Average Tenure
8 yrs 7 mos
Current Experience

Fastly

3 roles

Principal Security Engineer

Jan 2025Present · 1 yr 4 mos

Travel

Apr 2024Dec 2024 · 8 mos

  • Thru-hiked the Appalachian Trail.

Staff Security Engineer

Jan 2017Apr 2024 · 7 yrs 3 mos

  • Co-founded and led the Certainly group within Fastly, establishing a publicly trusted Certification Authority, which secured membership in the CA/B Forum and trust from major root stores including Apple, Mozilla, Microsoft, and Google.
  • Led architectural decisions, including HSM selection, physical and logical site security, business continuity and disaster recovery planning, container image design, and deployment architecture.
  • Authored core policies and operational procedures, focusing on key material security, cryptographic log integrity, network time security, and implementing physical security measures like video surveillance and access control systems.
  • Played a key role in incident handling, multi-vendor selection and integration, and penetration testing.
  • Contributed to the upstream codebases of Boulder, acme, and coen, all integral to the CA's operations.
  • Authored numerous internal tools in Golang, Python and Shell to enhance operational efficiency and security.
Cloud SecurityPrivate Key ManagementCryptographyGo (Programming Language)PKI

Cloudflare, inc.

Senior Systems Engineer, Security

Jan 2016Dec 2016 · 11 mos · San Francisco, CA · On-site

  • Microservice REST API design, Go development, with Python, PHP & SQL, targeting PKI applications.
Python (Programming Language)SQLPHPGo (Programming Language)PKI

Twitter

Senior Security Engineer

Feb 2014Nov 2015 · 1 yr 9 mos · San Francisco, CA · On-site

  • Lead engineering efforts for cryptography standards, secret distribution, certificate management and transport security.
PKI

Salesforce.com inc.

Principal Architect

Aug 2012Jan 2014 · 1 yr 5 mos · San Francisco, CA · On-site

  • Solve large-scale systemic problems involving Identity Management, Authentication, Authorization, Data Integrity and Single Sign-On with PKI, TLS, DSIG, SAML, OpenID, OAuth and OATH. Retooling data center infrastructure for a fully automated lifecycle.
PKI

Apple inc.

Security Architect, Consultant

Jan 2012Jun 2012 · 5 mos · Cupertino, CA · On-site

  • Advise senior management on solutions for problems germane to Identity Management, Authentication, Authorization and Directory Services Integration.

Noaa national environmental satellite, data and information service

Lead Storage Architect

Oct 2008Dec 2009 · 1 yr 2 mos · Suitland, MD · On-site

  • Development of next-generation systems architecture for NOAA Comprehensive Large Array-data Stewardship System in support of NPP, NPOESS, GOES-R and other future missions.

Peregrine productions

Chief Technology Officer

Jan 2008Jan 2011 · 3 yrs · Washington, DC

  • Provide strategic guidance on technology issues in support of business objectives. Responsible for hardware/software selection, procurement, deployment, operation and support. Assist with video/photo acquisition and editing/mastering. Perform business development activities including networking, marketing and corporate branding. Oversee business financials and operations.

Global science & technology

System / Network Architect

Jul 2006Dec 2011 · 5 yrs 5 mos · Washington D.C. Metro Area

  • Provide systems engineering and consulting services to US Federal Government agencies, including NASA, NOAA and DoD.

Nasa

System / Network Architect

Jul 2006Dec 2011 · 5 yrs 5 mos · Washington D.C. Metro Area · Hybrid

  • Oversee long-term project systems architecture, engineering and development activities for NASA Earth Observing System Clearinghouse (ESDIS/EOS/ECHO), NOAA Comprehensive Large Array-data Stewardship System (NESDIS/OSD/CLASS) and NASA SIVO Scientific Visualization Studio.
  • Propose, design and implement next-generation computing services including: single sign-on and identity management, hardware and service virtualization, L2/L3 network architecture, IPv6 deployment, storage abstraction/virtualization and cloud computing.

Nasa goddard space flight center

System / Network Architect

Jul 2006Oct 2008 · 2 yrs 3 mos · Greenbelt, MD · Hybrid

  • Responsible for specification and vendor selection of hardware, software and service purchases exceeding annual one million USD. Maximized ROI through novel vendor selection (Apple, Procurve).
  • Initiated migration of COTS and custom code from Solaris/SPARC and Linux/i386 to EM64T Mac OS X Server systems for significant cost savings and decreased management overhead.
  • Provided goals, direction and training to team of systems administrators. Oversaw long-term project systems development and engineering activities.
  • Proposed, designed and lead implementation of highly available and scalable Oracle (10g) database and application (J2EE) system architecture. Implementation incorporates multi-master read/write databases and dual-stack active-active application services.
  • Lead deployment of system virtualization and clustering, allowing for significant server consolidation, service scalability and improved disaster recovery capability.

Marijuana policy project

Senior Systems Engineer, Consultant

Apr 2006Jul 2006 · 3 mos · Washington, DC · On-site

  • Responsible for design, implementation and management of systems infrastructure supporting federal and state congressional lobbying efforts.
  • Creation of centrally managed, single sign-on environment using OpenLDAP, Kerberos V5, NFSv3 and NetBoot and BIND9 on Mac OS X Server 10.4.
  • Implementation of enterprise-class VoIP system using Asterisk on Fedora Core 5 (PowerPC).
  • Architecture of engineering solutions for expanding existing server environment, including backup solutions, high availability services and secure remote access.

New village media inc.

System Architect

Jun 2005Apr 2006 · 10 mos · Columbia, MD · On-site

  • Design of system architecture for high traffic, mission critical Internet service infrastructure utilizing commodity UNIX systems based on Apple Xserve, Xserve RAID and Xsan components.
  • Responsible for implementation and administration of Internet facing services, including HTTP, HTTPS, DNS, SMTP, IMAP, AFP, FTP, NFS and SSH, on Mac OS X Server 10.4 and FreeBSD 6.0 systems.
  • Perform comprehensive security auditing and remediation recommendations of database-driven web applications and supporting infrastructure.
  • Development of web-based content management systems using PHP and MySQL.

Intelli7

Senior Software Engineer

Nov 2004Feb 2005 · 3 mos · Washington, DC

  • Working with a team of developers to integrate packet capture and inspection technology with real-time data retrieval (libpcap, PHP, DHTML, XML + XSLT).
  • Porting C and C++ code from FreeBSD 5.2 (ia32) to Mac OS X 10.3 (ppc32) and FreeBSD 5.3 (sparc64).
  • Development of interactive web front end to FreeBSD-based security appliance using C++, XML and PHP.
  • Maintain standardized coding through the use of Subversion and code documentation.

Democratic national committee

Deputy National Field Director, IT

Apr 2004Dec 2004 · 8 mos · Washington, DC · On-site

  • Development of nationwide volunteer management database for the Kerry/Edwards 2004 Campaign using Mac OS X (10.3.x), PHP (4.x), Perl, XML and MySQL (4.1.x).
  • Planning and implementation of architecture for a central voting demographics database; used MySQL and PHP to merge various external data sources into one schema.
  • As the Director of the Information Systems team, establish security guidelines and standards of coding and testing the web-based volunteer applications.
  • Allocation of user requests and requirements to team members, ensuring timely completion of projects through detailed timelines and realistic milestones.
  • Preparation of technical tutorials and presentations for DNC staff members and volunteers, demonstrating the features of newly developed applications.
  • Contribute source patches to MySQL AB in order to correct bugs in the MySQL 4.x server code that occur when running on systems with 64-bit addressing.

America online

Senior Systems Programmer

Jan 2004Jun 2004 · 5 mos · Reston, VA

  • Development of SOAP/Web Services client-server system to automate network asset management reporting using Perl/XML.
  • Design and implementation of web-based network configuration system to manage Foundry layer 4 switching on AOL global networks.
  • Management of production Mac OS X (10.3/ppc64) and Linux (Red Hat AS3/ia32) systems, including software distribution/maintenance, monitoring and configuration.

Discovery communications

Network Planning Engineer

Mar 2003Nov 2003 · 8 mos · Silver Spring, MD

  • Development of server and network monitoring tools for worldwide infrastructure visibility. Designed and implemented custom network analysis / packet sniffing system based on Apple Xserve platform.
  • Primary liaison between Server Engineering and Network Planning departments for joint projects such as network authentication (LDAP/RADIUS/802.1X), IP telephony and server deployment (Lotus Notes, Mac OS X Server, QuickTime/Microsoft Streaming Content Delivery).
  • Responsible for company-wide (2500+ users) VPN design and deployment. Developed 802.11 security guidelines. Worked with outside security auditors to verify corporate defense policy implementation.
  • Presentation of domestic LAN/WAN utilization data to senior executives with recommendations for architecture restructuring.

Comtech mobile datacom corporation

Senior Software Engineer

Sep 1999Nov 2002 · 3 yrs 2 mos · Germantown, MD

  • High profile ground-up design and implementation of high-availability network operations center for use by US military. Built systems to handle DoD SBU satellite traffic using Mac OS X and FreeBSD servers and Cisco IOS/PIX network equipment.
  • Planning and deployment of secure networks for mission critical commercial and military applications across several continents. Responsible for coordination of WAN interconnections, network firewalls and intrusion detection systems, high-availability LAN design and computer hardware / software specifications.
  • Oversight of corporate information technology department to bring about reduced spending and increased reliability of company-wide computer systems. Implemented large-scale migration from Windows/Intel to Mac OS X/PowerPC workstations.
  • Lead software development teams on core network systems for global packet-switched satellite communications system. Developed software using C, C++, Perl and UNIX shell on Mac OS X and FreeBSD.

Education

University of Maryland

Master of Engineering - ME (incomplete) — Systems Engineering

Jan 2009Jan 2011

University of Maryland

Bachelor of Science - BS — Electrical Engineering

Jan 1995Jan 2000

University of Maryland

Bachelor of Science - BS — Computer Science

Jan 1994Jan 1999

Stackforce found 100+ more professionals with Cloud Security & Pki

Explore similar profiles based on matching skills and experience