Jim Manico

Co-Founder

Anahola, Hawaii, United States29 yrs 3 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Founder of Manicode Security with 15+ years in secure coding.
  • Leader of OWASP AISVS and ASVS projects for application security.
  • Java Champion and author of 'Iron-Clad Java'.
Stackforce AI infers this person is a Cybersecurity expert specializing in secure software development and application security standards.

Contact

Skills

Core Skills

Application SecurityArchitecture

Other Skills

Code ReviewEnterprise ArchitectureOWASPWeb Application SecurityWeb ApplicationsJavaScriptJavaPHPMySQLJSPCSSSecurityComputer SecurityJ2EESoftware Development

About

I help software engineering teams write secure code and now I'm encoding that expertise directly into AI. As founder of Manicode Security, I've spent 15+ years training developers, architects, and security engineers at enterprises worldwide. My work sits at the intersection of secure software development, application security standards, AI security standards, and AI-assisted engineering. I'm currently leading the OWASP AISVS (AI Security Verification Standard) a developer-verifiable control framework for AI systems and secure AI development. Standards Leadership Project Lead: OWASP AISVS (AI Security Verification Standard) Project Lead: OWASP ASVS (Application Security Verification Standard) Project Lead: OWASP Cheat Sheet Series Project Lead: OWASP Proactive Controls Former OWASP Global Board Member (2013–2016) Recognition 2018 Java Champion (Oracle) JavaOne Rockstar Speaker Author, Iron-Clad Java: Building Secure Web Applications (Oracle Press) Distinguished Lifetime Member, OWASP Foundation 24+ years software development | 14+ years application security Investor & Advisor I back and advise companies building the security infrastructure the industry depends on: Semgrep, EdgeScan, Nucleus Security, DefectDojo, RAD Security, Akto, Inspectiv, Levo.ai and others. Also a Fund LP at Aviso Ventures. Successful exits: Infrared Security (WhiteHat), WhiteHat Security (NTT), Brakeman Pro (Synopsys), Signal Sciences (Fastly), SecureCircle (CrowdStrike), BitDiscovery (Tenable), MergeBase (Finite State).

Experience

29 yrs 3 mos
Total Experience
5 yrs 1 mo
Average Tenure
7 yrs 1 mo
Current Experience

Edgescan

Strategic Technical Advisor

Jun 2023Present · 2 yrs 11 mos · Cobb, California, United States · Remote

  • Jim assumes to role of strategic technical advisor to help align our #RBVM #PTAAS & #ASM with emerging threats and industry direction.
Code ReviewArchitectureEnterprise ArchitectureOWASPApplication Security

Akto.io

Strategic Technical Advisor

Jun 2023Present · 2 yrs 11 mos

  • As a Strategic Technical Advisor for Akto.io, I leverage cybersecurity expertise to guide the company's API security technology vision and ensure the robustness and resilience of its solutions.

Aviso ventures

Fund Limited Partner

Apr 2022Present · 4 yrs 1 mo

  • At Aviso Ventures, we invest in companies that make the enterprise smarter, faster, and more secure. We help founders with actionable advice and access to capital, while never forgetting it's their company.

Mergebase

Investor and Advisor

Mar 2022Dec 2024 · 2 yrs 9 mos · Global

  • MergeBase gives companies a way to know where the biggest threats are, running live. MergeBase’s Software Composition Analysis platform manages vulnerabilities and license risk, during coding, building, deployment and running of your applications. It provides developer guidance based on risk, compatibility and popularity. It triggers warnings about vulnerabilities applications running in production including from third-party components and third-party software.
  • Successful exit in 2024!

Defectdojo

Board Member and Advisor

Jan 2022Present · 4 yrs 4 mos · Global

  • DefectDojo specializes in DevSecOps products. We obsess about making security scalable, useful, and actionable.

Rad security

Investor and Advisor

Aug 2021Present · 4 yrs 9 mos · Global

  • RAD Security is an event-driven SaaS platform built to automatically remediate Kubernetes security risks and enforce least-privileged access control across distributed cluster infrastructures.

Nucleus security

Investor, Board Member and Advisor

Apr 2019Present · 7 yrs 1 mo · Jacksonville, Florida

  • Nucleus is an application security risk tracking platform which helps organizations track entire portfolios of applications and their respective security issues. Nucleus provides integrations with dozens of security tools across the industry so you can have one pane of glass to view and understand the complexities of application security portfolio level risk.

Manicode security

Founder, CEO and Application Security Educator

Jan 2014Present · 12 yrs 4 mos · Anahola, Kauai, Hawaii · Hybrid

  • At Manicode Security we teach your developers to write secure code. We bring a combination of passion, style and years of research into all of our education offerings. Our education programs are designed for any web developer, architect, security professional or other software development professional who needs to build and maintain secure software.
Application Security

Brakeman security, inc.

Co-Founder

Jan 2014Jun 2018 · 4 yrs 5 mos · San Francisco Bay Area

  • Brakeman Security is a dedicated Ruby on Rails static analysis security engine company. Our main product, Brakeman Pro, was written by Neil Matatall, Jim Manico, and Dr. Justin Collins PhD, the author of the open source tool, Brakeman. Brakeman Pro was sold to Synopsys in June of 2018; an exciting successful exit for all involved.

Whitehat security

VP Security Architecture

Jun 2011Dec 2013 · 2 yrs 6 mos · Santa Clara, CA

  • Web application secure development educator and author. Conference speaker. Product Evangelist. Remediation practice support. WhiteHat was sold to NTT in March of 2019; a successful exit for all involved.

Independent contractor

Web Application and Security Architect

Feb 2010Jul 2011 · 1 yr 5 mos

  • Providing web application development and application security services to a wide variety of clients.

Owasp

OWASP Volunteer, Former OWASP Global Board Member

Jan 2008Present · 18 yrs 4 mos · Global

  • Active OWASP volunteer since 2008.
  • Co-leader and project manager of the OWASP AISVS (Artificial Intelligence Security Verification Standard), OWASP ASVS (Application Security Verification Standard), OWASP Proactive Controls and the OWASP Cheatsheet Series.
  • Elected OWASP Global Board Member from January 2013 to May 2016. Helped drive the strategic vision for the organization and continue to serve as an advisor to many OWASP leaders and members.

Aspect security

Application Security Architect

Aug 2007Feb 2010 · 2 yrs 6 mos

  • Lead Architect/Developer of an ongoing internal application security vulnerability management web application using J2EE/Java 1.5, Struts 1.3, Hibernate 3, JQuery/Javascript, xHTML/CSS, MySQL. Also developed a prototype XFORMS/Spring module for the Open Medical Record System project (openmrs.org) via Sun Microsystems, Partners in Health and TED.
  • Application security instructor and editor for 1, 3 and 5 day classes including "Building and Testing Secure Web Application", "Secure Coding for Java EE" and "Application Security Management".
  • Performed assessments of web applications and software products using architectural review, code review and penetration testing techniques. Experience identifying vulnerabilities associated with Web applications as well as system and network software. Produced detailed reports documenting vulnerabilities and specific mitigation recommendations.

Blue slate solutions

Senior Java Consultant

Jul 2005Dec 2005 · 5 mos

  • Played a key role on the Citibank project
  • Responsible for mastering and integrating the object-relational mapping tool Hibernate
  • Led the design and implementation of a web service data formatting component that had strict performance requirements
  • Developed a Java training package for Plug Power

Sans institute

Director of Vendor Relations, Software Engineer, Instructor

Aug 2004Jul 2005 · 11 mos

  • Senior software engineer and director for vendor sales team. ($2 million + in annual sales) Provide Business Development support to other Departments. Perform Vendor Floorshow Manager duties at all national conventions. Train and motivate sales staff. Provide in-depth metrics on department performance. Direct report to CEO. Instructor for the LAMP (Linux, Apache, MySQL and PHP) Track.

Codemagi inc.

Vice President Software Engineering

May 2002Feb 2008 · 5 yrs 9 mos

  • Cutting-edge website design. Application Security. Programming (Java, PHP, *ml, AJAX). Database (MySQL, Oracle, Posrgres). Software Engineering Management.

Kula high and intermediate

Chief Technologist

May 2002Aug 2004 · 2 yrs 3 mos

  • 5th-12th Grade Technology Educator, Physics Educator, Network Administrator, and Head of Technology Department for Elementary, Intermediate and High school.

Senior Java Consultant

Feb 1997May 2002 · 5 yrs 3 mos

  • Worked as independent consultant for GE, EchoStar, WebMD, Gazoontite, RateExchange, Fireman's Fund Insurance, Fortune 10 financial institutions and others.

Education

Siena University

Bachelor of Science (B.S.) — Computer Science

Jan 1993Jan 1997

Black Hat US 2007 Training

Building and Testing Secure Web Applications

Jan 2007Jan 2007

Secure Internet Presence - LAMP (Linux + Apache + MySQL + PHP)

Building and Testing Secure LAMP Web Applications

Jan 2004Jan 2004

Stackforce found 100+ more professionals with Application Security & Architecture

Explore similar profiles based on matching skills and experience