Steven Leath

CEO

28 yrs 9 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • 15+ years in Application Security Engineering.
  • Led SAST, DAST, and SCA programs at Fortune 500 companies.
  • Expert in embedding security into the SDLC.
Stackforce AI infers this person is a seasoned Application Security Engineer with a focus on enterprise-level security solutions.

Contact

Skills

Core Skills

Application SecurityApi SecurityDevsecopsSastDastContinuous IntegrationContinuous Deployment

Other Skills

REST APIsDetection EngineeringGolangGo (Programming Language)Microsoft SQL Server.NETCyber-securitySecuritySoftware DocumentationWeb ServicesDatabase AdministrationWeb DevelopmentPenetration TestingWeb ApplicationsIntegration

About

Senior Application Security Engineer with 15+ years of experience delivering secure software solutions and scaling AppSec programs across Fortune 500 companies, including Amazon, NBCUniversal, and Aya Healthcare. I specialize in embedding security into the SDLC, developing custom detection logic, and automating security tooling with a developer-first mindset. At Aya, I lead the implementation of SAST, DAST, and SCA programs using open-source tools like Semgrep and Nuclei, building custom rulesets and security metrics that enable proactive risk reduction. Previously at Amazon, I focused on API security strategy and tooling in Golang for large-scale GraphQL environments. I bring a hands-on engineering approach with deep expertise in secure coding, DevSecOps, and threat modeling. Passionate about empowering development teams with actionable security insights, I build programs that scale with velocity, not friction. Core Strengths: ✅ Application Security Strategy & Architecture ✅ Secure SDLC | Threat Modeling | CI/CD Security ✅ Golang, C#, Node.js, Python | Docker | Kubernetes ✅ SAST (Semgrep, Opengrep, Checkmarx), DAST (Nuclei), SCA (Snyk, Nexus IQ) ✅ AWS, Terraform, GitLab CI, Jenkins, .NET Core

Experience

28 yrs 9 mos
Total Experience
2 yrs 10 mos
Average Tenure
4 yrs
Current Experience

Amazon

Sr. Application Security Engineer

May 2022Present · 4 yrs

REST APIsAPI SecurityApplication SecurityDetection EngineeringGolangGo (Programming Language)

Nbcuniversal media, llc

Senior Application Security Engineer

May 2019May 2022 · 3 yrs · United States

  • Creating a DevSecOps environment. Helping engineers shift left at scale. Focusing on CICD Jenkins/AWS Codebuild/GitLabCI and Container Security via Twistlock. Creating guidelines, policy, best practices.
REST APIsDevSecOps

Northwestern mutual

2 roles

Lead Application Security Engineer

Nov 2018May 2019 · 6 mos

  • Working with SAST, DAST, SCA, Threat modeling as code tools.
REST APIsSASTDAST

Sr. Application Security Engineer

Nov 2017Nov 2018 · 1 yr

  • Code reviews, Pentesting, Helping with Continuous Deployments and Continuous Integration. Working with Python and Gitlab to create a pipeline integrating tools such as Checkmarx, Clair, and Blackduck.
REST APIsContinuous IntegrationContinuous Deployment

Vault44

Founder & CEO

May 2017Apr 2024 · 6 yrs 11 mos

Pentegra retirement services

Sr. Software Security Developer

Jun 2014Oct 2017 · 3 yrs 4 mos

  • Redesigned legacy WCF Services and Web Services for a centralized series of WebAPI 2 endpoints. Utilizing C#, SQL Database, Entity Framework, JSON, MVC and hosted on IIS7. Database integration with Charles Schwab RT record keeping systems.
  • ]• Designed, developed and maintained an (RMD) Retirement minimum distribution system which consisted of AngularJS frontend, C# middleware and SQL Server backend. This project began as a maintained excel document that was unmanageable. And went to a full featured internal web application utilized by 40 – 50 internal staff members. With integration points into Charles Schwab RT record keeping system.
  • Managed security on all applications and websites to meet NIST Identity Management standards. By designing, developing and maintaining internal security framework. Worked to establish best practices and conducted training session with internal employees. Worked with company on FFIEC compliance throughout the company.
  • Evaluated and configured Centrify single sign on and multi-factor authentication throughout Pentegra. Implemented the use of JWT’s and SAML integration for MFA with Centrify.
  • Created secure programming practices for developers through using Team Foundation Server and following Microsoft Secure SDLC. Which allows us to consider security throughout our internal SDLC process and not just at the very end.
  • Evaluated wide variety software solutions from outside vendors for various duties throughout the company from internal operations, sales, security, and development.
  • Configuration of test, dev, and production environments on Windows Server 2012 an IIS 7.
  • To meet the FFIEC and NIST standards created and managed the x.509 certificates to sign internal bearer tokens, to encrypt development environment traffic from databases, and to establish separation between QA, Dev, and Production web applications.
REST APIs

Icon international, inc.

Sr. Software Developer/Manager

Mar 2013Jun 2014 · 1 yr 3 mos · Stamford, CT

  • Managing development team. Mentored junior developers, conducted code reviews as well as managed agile development environment.
  • Created ICON People Finder or IPF. A web application that utilized AJAX/Jquery and Entity Framework 4.0/ MS SQL Server 2008 and Google maps API to locate people around the company and where they sit. Fully integrated into MS Outlook as an outlook addin in C#.
  • Created Billing application that is a desktop application that calls a WCF Service with PDF combining service as well as billing and accounting information. Utilized Entity Framework 4.0 as well as Tallcomponents for process PDF files. Created windows workflow with WF, WCF and AppFabric.
  • Created a Ticket System that’s allows emails to be tracked in three different systems integrated with legacy Ticketing system in Desktop application as well as Bugnet application. Utilized Entity Framework 4.0 with Linq. MS SQL Server 2008 backend with Outlook integration.
  • Created customizations to legacy Microsoft CRM application in Javascript and C#. Utilizing web services.
  • Maintaining legacy applications written in VB.NET/C#, Access 97, Micrsoft CRM.
  • Maintained database with T-SQL creating stored procedures as well as optimizing indexes using Red Gate tools.

Vodafone

Sr. .NET Developer

Aug 2011Dec 2012 · 1 yr 4 mos · Sandy Hook, CT

REST APIs

Canine companies

Software Developer

Feb 2010Aug 2011 · 1 yr 6 mos

  • Canine Companies, Wilton
  • Converting legacy vb6 applications to vb.net and C#.
  • Developing and maintaining web forms for .Net intranet applications.
  • Maintenance of blackberry application written in C#.
  • Working with marketing department to develop relevant email campaigns.
  • Used AJAX and Jquery on Webforms throughout the intranet and public www.caninefence.com
  • Created and maintained Winforms in VB6 legacy application.
REST APIs

Sikorsky aircraft

Developer

Jun 2009Dec 2009 · 6 mos

  • Stratford
  • Developed Office 2007 Open Office applications at Sikorsky, using Visual Studio 2005 and optimizing SQL statements and mviews in an Oracle 11g data warehouse environment.
  • Used XML data to make and construct seamless office solutions.
  • Created internal MVC websites with graphs using ChartFX components for graphing statistical data in the Business intelligence department. Pulling Data from Oracle datawarehouse.
  • Developed and maintained complex PL/SQL expressions using analytical functions and sub-queries to gather information from the Oracle Data Warehouse.
  • Optimized and maintained legacy SQL expressions that were currently in production for performance.
  • Incorporated AJAX for front-end work utilizing JQuery JavaScript library. Created custom server controls for reuse in BI department. The jqeury motion functions allowed for seamless integration and effects for the presentation of statistical data and or metrics.

Vatti-manhattan group

NET Developer

Jun 2008Mar 2009 · 9 mos

  • Created Website Design for Software Company using Adobe CS3, Action Script 3, Visual Studio 2008, and JavaScript.
  • IIS 6 + 7 configuration of websites and internal sites.
  • Helped modify and upgrade legacy software in C# which was called CC.
  • Maintained in house windows desktop applications using web services and C#.
  • Created and deployed new software suite called XM. Designing data driven design time custom controls using AJAX and CS3.
  • Used XML mapping to create custom data sources for design time controls.
  • Created SQL stored procedures for security purposes that were used in production. Also created Data Access Layer that utilized these stored procedures in the web and desktop applications.
  • Utilized Jquery to create motion effects at runtime combined this with the custom server controls that I created.
  • Handled deployment of new software and roll out for testing.
  • Worked to upgrade the old software connections to new software connections through SQL Server 2008.
  • Set up Vault Client and repositories for working in group of 5 developers.

Broads unlimited

Jr. System Administrator

Feb 2007Feb 2008 · 1 yr

  • Developed 85broadsfoundation website. Created CSS, HTML, Flash, and JavaScript code for project.
  • Prepared images and content for upload to site.
  • Installed Radiant Content Management System for ease of use for Users on a Linux OS.
  • Maintained a small network of 35 users. Setup a Hybrid network of Apple and PCs.
  • Setup up Blackberrys and I-phones with email, contacts and calendar accordingly.
  • Setup users with documentation on use of website and network VPN and networked hard drives.
  • Support for hardware and software issues [Outlook 2003, Entourage, Thunderbird, among other email clients as well as managed a hosted exchange setup.

Pulse creative

Web Developer

Jan 2007Jan 2008 · 1 yr

85 broads

Web Developer/Administrator

Jan 2007Jan 2007 · 0 mo

Boehringer-ingelheim pharmaceuticals

System Analyst

Apr 2006Jan 2007 · 9 mos

  • Supported over 30,000 remote users nationwide on a in house web based application for medical representatives.
  • Supported in-house Seibel Software which included database extracts and creation of queries.
  • Handled MS Office issues, Windows XP/2000 OS issues, Cisco VPN client issues, Active Directory, and SAP.
  • Used net meeting and web-ex to remotely access computers.
  • Handled Blackberry 7200 series issues such as, synchronization issues and password resets.

Sentinel business solutions

Senior Technician

Apr 2005Apr 2006 · 1 yr

  • Conducted tests and analysis on OS and firmware of smart phone devices.
  • Tested GPRS and 802.11b/g on devices returned from the field using C# and SQL Server.
  • Wrote technical build procedures on Intermec devices and custom client applications.
  • Configured certain features from PDA devices such as SMS so that it wouldn't interfere with custom software on Windows CE.
  • Configured Symbol, Intermec, and Zebra products for out of box field use.
  • Created SQL expression for reporting purposes.

Ge world headquarters - international patents office

Office Manager/Workflow Efficiency Expert

Sep 2001Aug 2002 · 11 mos

  • Managed and analyzed Human Resources to design and implement a streamlined process for filing patents worldwide.
  • Designed and implemented a customized PIP System for the purpose optimal workflow efficiency and productivity.

Leathal1s, llc

Web Developer / Network Engineer

Aug 1997Dec 2014 · 17 yrs 4 mos

  • Maintenance of e-commerce portals for some clients created shopping carts and ways of handling payments.
  • Web application design and setup using Flash, PHP, ASP.NET or static HTML sites.
  • Setting up full ecommerce websites with Paypal shopping cart.
  • Troubleshooting network connectivity issues. Maintaining remote client sites.
  • Setup of Cisco, Netgear, and Belkin wireless routers and various switches.

Education

University of Maryland Global Campus

Master of Science (MS) — Cyber security

Jan 2015Jun 2017

American Intercontinental University

Bachelors Science — Information Technology

Jan 2012Jan 2013

Stackforce found 100+ more professionals with Application Security & Api Security

Explore similar profiles based on matching skills and experience