Daniel Gellman

CEO

Wesley Chapel, Florida, United States14 yrs 4 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Led application security team to enhance performance.
  • Founded a cybersecurity consulting firm.
  • Integrated AI into security workflows.
Stackforce AI infers this person is a Cybersecurity expert with a strong focus on application security and vulnerability management.

Contact

Skills

Core Skills

Application Security ArchitectureSecurityPenetration TestingCybersecurityRed TeamingApplication SecuritySoftware Development

Other Skills

Application Security TestingArtificial IntelligenceAuthenticationAuthorizationC++CI/CDCI/CD PipelinesCSSComputer HardwareContainer ScanningData ConsultingData FeedsDynamic AnalysisHIPAA ComplianceHTML

About

Experienced Security Engineer with a demonstrated history of working in the computer software industry. Skilled in PHP, Servers, Windows Server, Java, and Networking. Strong engineering professional with a Master’s Degree focused in Computer and Information Systems Security/Information Assurance from University of Maryland College Park.

Experience

14 yrs 4 mos
Total Experience
2 yrs 4 mos
Average Tenure
4 yrs
Current Experience

Confidential

2 roles

Application Security Manager

Promoted

Jun 2023Present · 3 yrs · Remote

  • Lead a team of engineers to improve the application security team's efficiencies, working with team members to enhance their performance in areas where improvement was indicated.
  • Conducted multiple PoC evaluations to replace existing tooling: SAST, SCA, Container Scanning, and Secrets Detection.
  • Partnered with other teams in the organization to promote shift left adoption. Built additional tooling, such as validation, to filter out noise and complement acquired tools. Created an extensible secrets validator to reduce false positives to 0.
  • Established validation routines for all critical secret types, minimizing additional pipeline time to approximately 2 minutes on average and enriching the finding output to be more targeted for the organization.
  • Lead the creation and optimization of rules for improving SAST findings using artificial intelligence aids.
  • Collaborated with sister security teams to create paradigms and other documentation to promote security awareness and give engineers a direction on what right looks like. Developed standards for tool-finding evaluation in escalation cases.
  • Helped integrate artificial intelligence into security workflows, allowing in-house LLMs to review changes and provide quality initial triage and prioritization.
Application SecurityArtificial IntelligenceSASTSCAContainer ScanningSecrets Detection+2

Senior Application Security Engineer

Jun 2022Jun 2023 · 1 yr · Remote

  • Conduct penetration tests of critical infrastructure and business areas.
  • Review existing processes for inefficiencies and implement new processes to guide more targeted testing.
  • Partnered with engineering team(s) to provide security insights during architecture design and review periods.
  • Started implementing security tooling directly into CI/CD pipelines for enhanced security oversight. Created enrollment process for onboarding new repositories into existing SAST tooling.
  • Helped to reshape the application security team and processes by assisting team members in building their development contacts, re-organizing the team around products, balance alignments to ensure a fair workload, and helping team members to better schedule/timebox penetration tests.
Penetration TestingApplication SecuritySecurity InsightsCI/CD PipelinesApplication Security Architecture

Blackline

Application Security Engineer

Jan 2019May 2022 · 3 yrs 4 mos · Los Angeles Metropolitan Area

  • Designed new authentication/authorization mechanism to improve performance while breaking monolith into microservices.
  • Provided guidance on secure implementation of event bus messaging system.
  • Founded Red Team program – conducting multiple covert operations.
  • Trained and mentored people to through GWAPT training program with 100% passing rate of GWEB certification.
  • Redefined manual penetration testing process to improve reporting, bug tracking, repeatability, and efficiency.
  • Worked as imbedded security presence within development teams, assisting them with designing secure solutions.
  • Perform static and dynamic analysis of new & existing development efforts.
  • Perform security architecture reviews of new development solutions.
  • Review requested vendors security posture before company purchases licenses.
AuthenticationAuthorizationMicroservicesRed TeamingStatic AnalysisDynamic Analysis+1

Warner bros. entertainment group of companies

Senior Security Engineer

Feb 2018May 2018 · 3 mos · Greater Los Angeles Area

  • Perform Vulnerability Assessments on web applications.
  • Perform Security Architectural Design review of existing application and infrastructure.
  • Perform Security Architectural Design review of new applications as they arise.
  • Assist in Qualys vulnerability management across entire business.
  • Update & streamline security posture questionnaires in order to make them more effective and easier to use by all business units.
Vulnerability AssessmentsSecurity ArchitectureQualysSecurity

Axis cyber labs

Co-Founder

Jul 2017Jan 2023 · 5 yrs 6 mos

  • Axis Cyber Labs, North American cybersecurity and data consulting firm established in 2017, is on the mission to propel the advancement of cybersecurity awareness, education and to serve as a proactive force to counter cybersecurity threats and attacks in the digital era.
  • The company provides education, training, and offers a complete suite of cybersecurity expertise, tools, and techniques to help safeguard proprietary and confidential business data and applications.
  • We partner with our clients to evaluate and analyze the integrity of business infrastructure and explain vulnerabilities and cyber threats many individuals and companies are unwillingly exposed to every day.
  • Axis Cyber Labs' vision and values stem from the founders’ inherent belief in fundamental human rights, and that integrity, privacy, and confidentiality of personal, financial, medical, or any other proprietary data must be governed and protected.
  • Our team of cybersecurity experts specializes in penetration testing, vulnerability assessments, cybersecurity, and data consulting, as well as Cybersecurity awareness and education.
  • We deliver a custom-tailored defense action plan for our clients and ensure compliance with industry standards.
CybersecurityData ConsultingPenetration TestingVulnerability Assessments

Jack henry & associates

Application Security Engineer

Aug 2016Jan 2018 · 1 yr 5 mos · Greater Atlanta Area

  • Build and maintain the internal manual application security-testing program.
  • Manage projects from start to completion in order to allow teammates to work effectively.
  • Create a perimeter defense program for all external facing web application through the use of offensive security techniques to actively patrol and monitor any application for weaknesses.
  • Perform internal manual penetration testing assessments.
  • Perform vulnerability scans as requested.
  • Perform security architecture design reviews and propose suggestions for properly configuring applications and systems based on presented design concepts.
  • Collaborate and improve relations with company development teams in order to better security posture and insure proper remediation of any found vulnerabilities.
  • Remediation retesting to ensure that vulnerabilities found by third party testing was corrected.
Application Security TestingPenetration TestingVulnerability ScansSecurity ArchitectureApplication Security

Dell secureworks

Senior Security Analyst

Aug 2015Aug 2016 · 1 yr

  • Perform accurate and precise real-time analysis and correlation of logs/alerts from a multitude of client devices with a focus on the determination of whether said events constitute security incidents
  • Analyze and assess security incidents and escalate to client resources or appropriate internal teams for additional assistance
  • Manage all customer interactions in a professional manner with emphasis on customer satisfaction
  • Handle clients requests and questions received via phone, e-mail, or an internal ticketing system in a timely and detail-oriented fashion in order to resolve a multitude of information security related incidents
  • Interact with, configure, and troubleshoot network intrusion detection devices and other security systems via proprietary and commercial consoles
  • Utilize internal guidelines in order to properly handle client requests and questions
Log AnalysisIncident ResponseNetwork SecuritySecurity

Turner (turner broadcasting system, inc)

Junior Software Developer

Sep 2013Sep 2015 · 2 yrs

  • Write plug-ins and XML Transforms to create new data feeds for consumption by multiple NBA sports outlets including: NBA.com, TNT, and NBA Digital. I have recently been put in charge of a project to create a proof of concept application that will read data from a supplied PDF file and transform it into an XML feed for later consumption. I am also working on another project to make use of new technology that will document athlete locations on a basketball court and allow for speculative analysis such as if he should have gotten a rebound or blocked a shot.
Software DevelopmentXMLData Feeds

Medicity

iNexx Escalations Programmer

Jan 2011Sep 2013 · 2 yrs 8 mos

  • Create new and modify existing JSP pages to improve functionality and usability both on the client and support side. Supporting end-user functionality issues with applications involving J2EE, JSP pages, or Javascript errors. Assisted in running a penetration test using the Backtrack operating system. We tested for data encryption during transmission as well as for SQL injection, cross-site scripting vulnerabilities, as well as proper user data sanitation using the various tools provided on the operating system to identify vulnerabilities in the iNexx platform, featured applications, and related servers to insure HIPPA compliance and security of patient record transmission between a hospital and doctors office as well as between doctors offices.
  • Achievements:
  • Identified critical errors in production code that could have potentially lead to customers across the country and applied a fix before the issue became widespread.
  • Identified compatibility issues between versions of code that could have lead to issues across one state.
  • Created web pages that assisted the support team in identifying minor bugs.
  • Created web pages that eased the workload on the support team, allowing them to automate job duties.
  • Create and implement new workflow processes to streamline support procedures and improve the customer experience.
  • Created client facing Support page to allow for easy submission of trouble tickets as well as allow clients to request and start a remote support session.
  • Helped to identify security issues during penetration tests of company applications and servers.
JSPPenetration TestingHIPAA ComplianceSecurity

Wipro

Project Engineer

Jan 2010Jan 2010 · 0 mo

Education

University of Maryland

Master’s Degree — Computer and Information Systems Security/Information Assurance

Jan 2015Jan 2017

Southern Polytechnic State University

Masters Certificate — Computer and Information Systems Security/Information Assurance

Jan 2013Jan 2014

Southern Polytechnic State University

Bachelor of Science (B.S.) — Information Technology

Jan 2007Jan 2010

University of Tampa

Jan 2005Jan 2006

Stackforce found 100+ more professionals with Application Security Architecture & Security

Explore similar profiles based on matching skills and experience