
Application Security, AI Security & Secure Engineering
Practical application security for software teams.
I help engineering teams build secure applications through secure code review, threat modelling, vulnerability management, AI security, penetration testing, and CI/CD security automation.
I lead application security work across engineering teams, combining hands-on technical testing with clear remediation guidance, secure design support, and application security maturity improvement across enterprise environments. My credentials include Certified Information Systems Security Professional (CISSP) and Offensive Security Certified Professional (OSCP).
Focus
The work I care about most sits where technical security testing, engineering delivery, and clear risk decisions meet.
Application security leadership
Helping teams make security decisions earlier, remediate issues effectively, and improve AppSec maturity without slowing delivery.
Secure software delivery
Embedding secure design, code review, threat modelling, vulnerability management, and automated checks into everyday engineering workflows.
AI security
Reviewing AI-enabled systems, assessing AI-generated code, and applying modern models and tooling to practical AppSec workflows.
Experience
Lead Security Engineer - Applications
May 2026 - Present
Providing practical application security guidance, hands-on remediation support, and technical leadership for engineering teams. My work covers secure code review, reviews of AI-enabled systems, threat modelling, vulnerability remediation, CI/CD security automation, and secure design support, with a focus on making AppSec effective, repeatable, and easy for development teams to adopt.
Senior Security Engineer - Applications
Oct 2025 - May 2026
Supported engineering teams with hands-on application security testing, secure code review, practical remediation guidance, threat modelling, AI-assisted vulnerability analysis, and automated security checks across the software development lifecycle.
Senior Application Security Engineer
Jul 2025 - Present
Delivering focused application security health checks for software teams. Each engagement uses AI-assisted secure code review to target the high-risk areas where serious issues usually live, then produces a clear, actionable written report and a one-to-one debrief that gives teams either reassurance or a concrete remediation plan.
Application Security Manager
Mar 2023 - Oct 2025
Led application security improvement across an enterprise SaaS environment, including technical testing, security review, generative AI security review, AI-generated code assessment, AI safety guardrails, and risk guidance for engineering teams.
Independent Security Researcher
Synack Red Team
Nov 2021 - Oct 2025
Participated in private security testing engagements across web applications, mobile applications, and infrastructure alongside full-time employment, reporting vulnerabilities through structured responsible disclosure processes.
Senior Security Engineer - Applications
Mar 2022 - Mar 2023
Helped improve application security across a large global engineering environment, supporting teams with secure design decisions, practical AppSec guidance, threat modelling, and DevSecOps-focused ways of working.
Application Security Specialist
Mar 2020 - Mar 2022
Supported application security improvement across a global financial services environment, covering secure code review, web application penetration testing, vulnerability scanning, platform assurance, security reporting, and AppSec tooling evaluation.
Business Systems Manager and earlier operations roles
Oct 2006 - Mar 2020
Progressed through operational, analytical, and systems-focused roles before moving into Business Systems Management in 2015. Led support, improvement, and integration of internal business systems across finance, operations, and wider enterprise processes.
Credentials
Selected Work
Public projects where I publish, maintain, and review practical application security guidance, tooling, and training material.
JustAppSec
Creator, maintainer, and engineer
An application security practice I created and maintain, offering focused security health checks and AI-assisted secure code review for software teams. Alongside running it, I stay hands-on in the engineering work, from secure code review and vulnerability analysis to threat modelling and DevSecOps guidance.
Visit JustAppSecThe CyberSec Lounge
Creator and content reviewer
An independent cyber security learning and resource site created to share practical guidance, training material, and industry-focused content.
Visit The CyberSec Lounge