Rami McCarthy

CEO

Stockholm, Stockholm County, Sweden11 yrs 1 mo experience

Key Highlights

  • Expert in scaling security programs for cloud-native companies.
  • Advocate for empathic security and business-driven security value.
  • Proven track record in establishing security disciplines.
Stackforce AI infers this person is a Security Expert specializing in Cloud Security and Risk Management.

Contact

About

Experienced in starting and scaling security programs for cloud-native companies. I believe in empathic security, guardrails over gates, and using security to drive business value.

Experience

11 yrs 1 mo
Total Experience
2 yrs 2 mos
Average Tenure
1 yr 11 mos
Current Experience

Wiz

Principal Security Researcher

Jan 2025Present · 1 yr 4 mos · Remote

  • I "work for the security industry, at Wiz"

Devarmor

Advisor

Oct 2024Present · 1 yr 7 mos

  • Helping figure out how to apply AI and code comprehension to scale product security and code reviews.

P0 security

Advisor

Jun 2024Present · 1 yr 11 mos

  • Helping an organization that's helping organizations govern cloud access for all identities - human and machine

Latio tech

Advisory Board Member

Jun 2024Present · 1 yr 11 mos

  • Providing expert guidance, oversight, and second opinions to a practitioner run, practitioner focused security industry advisory startup

Career break

Personal goal pursuit

Mar 2024Jan 2025 · 10 mos

  • I took a sabbatical, and relocated to Stockholm!
  • I spent my time advising startups, writing on security, reading 80+ books, and overall had a great time

Kondukto

Advisor

Jan 2023Jan 2025 · 2 yrs

Figma

Security Engineer

Aug 2022Feb 2024 · 1 yr 6 mos · Remote

  • Helped establish Infrastructure Security as a discipline, and led security partnership for the Infrastructure Area
  • Ask me about:
  • The Path to Zero Touch Production
  • Bootstrapping security as part of a company wide migration to EKS
  • Building industry leading security for Terraform Automation
  • Fighting fires, and making attackers' lives difficult
  • Side quests to save millions of dollars

Cedar

2 roles

Staff Security Engineer, Manager

Mar 2022Jul 2022 · 4 mos

  • In addition to previous responsibilities:
  • Manage a team of 3 (2 analysts, 1 product security engineer)
  • Represent security on Cedar's Architecture Steering Group

Staff Security Engineer, Tech Lead

Nov 2020Mar 2022 · 1 yr 4 mos

  • Third security hire, helped define and grow the program:
  • Security Partner for highest-risk portfolio of Data, Platform, and Integrations pillars. 93% CSAT in Engineering.
  • Created security interview rubrics and sat on hiring committee for DevOps, IT, and Security hires. Sourced Staff and Manager hires. Successfully hired and on-boarded Security Analysts and a Product Security Engineer.
  • DRI for Cloud (AWS) Security, Security Operations, Incident Response, Pentesting, post-M&A integration of Cedar and OODA Health security programs
  • Introduced and matured business-facing Rapid Risk Assessments and Vendor Risk procedures
  • SME for PCI Compliance (Service Provider Level 1), supported sales via security due diligence and customer exec conversations
  • Supervised Proof-of-Value exercises for MDR, SAST, DAST, SIEM, CSPM and Vulnerability Management platforms - driving cost efficiencies through balance of open-source utilities and investments in commercial partners
  • Led values identification exercise and evangelized Security Values internally and externally (https://decode.cedar.com/defining-cedars-security-values/)
  • In a team of two, designed, deployed, and operated Cedar's first API (~250k requests a day)

Ncc group

Senior Security Consultant

Jul 2017Oct 2020 · 3 yrs 3 mos

  • Joined NCC Group through the acquisition of VSR.
  • Security Consultant: July 2018-June 2020
  • Conducted 50+ security engagements, including web and mobile applications (iOS, Android), cloud security (AWS, GCP), code review (Ruby, JS, Python, PHP, Java), M&A (pre- and post-terms), staff augmentation (product security, vendor security, and bug bounty, spent a cumulative six months working for multiple FAANG companies in 6 week or 3 month stints) and even physical security
  • Technical lead for complex engagements, serving the Group's highest-profile clients, orchestrating teams of up to 10, and supporting over $1 million in sales through scoping and pre-sales efforts
  • Spearheaded the North American Cloud Working Group, standardizing and improving sales and delivery

Vsr

2 roles

Security Consultant

Promoted

Jun 2017Oct 2020 · 3 yrs 4 mos

  • (acquired by NCC Group)
  • Co-op Jul-Dec 2017, part time through June 2018
  • white/gray/blackbox web application penetration tests
  • internal and external networks
  • mobile applications
  • Social engineering (and vishing, smishing)
  • Broke into at least one building (physical security assessment)
  • As an intern, logged the most hours in the office on super smash bros

Security Consultant

Jul 2016Dec 2016 · 5 mos

  • mostly defending my machine from being used as a ctf by coworkers
  • vulnerability scans, external network penetration tests, CRUD web application assessments

Sixgill

Software Development Intern

Jun 2015Aug 2015 · 2 mos · Yokneam Illit, IL

  • Developed secure full-stack login flow for venture funded cyber security startup using Flask and OrientDB. Contributed to compilation of threat intelligence packages for F500 clients.

Northeastern university

Senior ResNet Technician

Jul 2014Apr 2018 · 3 yrs 9 mos · Boston, MA

  • Software and hardware technical support for students and faculty. Trained dozens of junior staff. Automated malware remediation (24h -> 10m). Automated scheduling notifications.

Milton public library

Page

Jan 2012Jun 2014 · 2 yrs 5 mos · Milton, MA

Education

Northeastern University

Computer Science With Concentration in Cyber Operations — Computer Science

Jan 2014Jan 2018

Brandeis University - Online

Master of Science - MS — Information Security Leadership

Jan 2019Jan 2021

Milton High School

Jan 2010Jan 2014

Rami McCarthy - CEO | Stackforce