Steven Leath — CEO
Senior Application Security Engineer with 15+ years of experience delivering secure software solutions and scaling AppSec programs across Fortune 500 companies, including Amazon, NBCUniversal, and Aya Healthcare. I specialize in embedding security into the SDLC, developing custom detection logic, and automating security tooling with a developer-first mindset. At Aya, I lead the implementation of SAST, DAST, and SCA programs using open-source tools like Semgrep and Nuclei, building custom rulesets and security metrics that enable proactive risk reduction. Previously at Amazon, I focused on API security strategy and tooling in Golang for large-scale GraphQL environments. I bring a hands-on engineering approach with deep expertise in secure coding, DevSecOps, and threat modeling. Passionate about empowering development teams with actionable security insights, I build programs that scale with velocity, not friction. Core Strengths: ✅ Application Security Strategy & Architecture ✅ Secure SDLC | Threat Modeling | CI/CD Security ✅ Golang, C#, Node.js, Python | Docker | Kubernetes ✅ SAST (Semgrep, Opengrep, Checkmarx), DAST (Nuclei), SCA (Snyk, Nexus IQ) ✅ AWS, Terraform, GitLab CI, Jenkins, .NET Core
Stackforce AI infers this person is a seasoned Application Security Engineer with a focus on enterprise-level security solutions.
Experience: 28 yrs 9 mos
Skills
- Application Security
- Api Security
- Devsecops
- Sast
- Dast
- Continuous Integration
- Continuous Deployment
Career Highlights
- 15+ years in Application Security Engineering.
- Led SAST, DAST, and SCA programs at Fortune 500 companies.
- Expert in embedding security into the SDLC.
Work Experience
Amazon
Sr. Application Security Engineer (4 yrs)
NBCUniversal Media, LLC
Senior Application Security Engineer (3 yrs)
Northwestern Mutual
Lead Application Security Engineer (6 mos)
Sr. Application Security Engineer (1 yr)
Vault44
Founder & CEO (6 yrs 11 mos)
Pentegra Retirement Services
Sr. Software Security Developer (3 yrs 4 mos)
ICON International, Inc.
Sr. Software Developer/Manager (1 yr 3 mos)
Vodafone
Sr. .NET Developer (1 yr 4 mos)
Canine Companies
Software Developer (1 yr 6 mos)
Sikorsky Aircraft
Developer (6 mos)
Vatti-Manhattan Group
NET Developer (9 mos)
Broads Unlimited
Jr. System Administrator (1 yr)
Pulse Creative
Web Developer (1 yr)
85 Broads
Web Developer/Administrator (0 mo)
Boehringer-Ingelheim Pharmaceuticals
System Analyst (9 mos)
Sentinel Business Solutions
Senior Technician (1 yr)
GE World Headquarters - International Patents Office
Office Manager/Workflow Efficiency Expert (11 mos)
Leathal1s, LLC
Web Developer / Network Engineer (17 yrs 4 mos)
Education
Master of Science (MS) at University of Maryland Global Campus
Bachelors Science at American Intercontinental University