xterm — apropos jarred
apropos jarred
engineering(3)
led engineering teams from brand-new recruits to principals
team_building(3)
built pentest teams, SDLC programs, consulting benches, and security orgs from scratch
architecture(3)
cloud, mobile, IOT, containers, packaged apps; threat modeling and secure design patterns
consulting(3)
direct engagement with clients, auditors, and senior business stakeholders
compliance(3)
SOC2, HIPAA, PCI-DSS, GDPR — both as assessor and as program leader
public_speaking(3)
BSides, RSA, PasswordsCon; internal evangelism to senior execs and peer mentoring
man 3 engineering team_building architecture consulting compliance public_speaking
JARRED(3) Subject Matter Expertise JARRED(3)

ENGINEERING

Led engineering teams at all levels of the organization — from brand-new recruits to principals — providing mentorship and helping to align business objectives to professional goals. When necessary, I can occupy the role of an SME and contribute my years of engineering experience to any discussion. I remain familiar with the tools and techniques used in software development, security engineering, vulnerability management, and penetration testing.

TEAM AND PROGRAM BUILDING

Building and maturing successful security organizations is the backbone of my management experience. I have built penetration testing teams, Secure Development Lifecycle programs, consulting benches, and strong security organizations from the ground up. I lead from the front by example, encouraging and inspiring those who work with me to bring their all to each challenge we face together.

ARCHITECTURE

Expertise in modern software architectures across cloud, mobile, IOT, containers, and traditional packaged applications. I'm comfortable contributing directly to secure product design, or leading teams of senior architects responsible for threat modeling, secure design patterns, requirements, and influencing the direction of broad and complex product portfolios.

CONSULTING

I have spent a significant portion of my career interacting directly with clients, auditors, and senior business stakeholders. I excel at translating requirements into plain language, understanding business objectives, and providing the right direction at the right time.

COMPLIANCE

Security has significant overlap with compliance, and I have worked as both an assessor of compliance as well as a leader with direct oversight of SOC2, HIPAA, PCI-DSS, and GDPR programs. I have implemented programs which entwine security and privacy-by-design as part of the Secure Development Lifecycle, and I remain up-to-date on the legal and compliance landscape relating to data protection and cybersecurity in both the United States and Europe.

PUBLIC SPEAKING

Speaking in front of others has long been one of my core competencies. As a lifelong evangelist of security and privacy, I have delivered talks at major industry conferences and events and mentored up-and-coming security professionals. I regularly deliver internal presentations focused on the current and future state of application security to other senior business executives.

See also man jarred — section PUBLICATIONS — for a list of talks and events.

SEE ALSO

finger(1) ./who I am right now man(1) ./resumethe long-form history sentesecurity(7)https://sentesecurity.io
_