Résumé examples › Application Security Engineer

Application Security Engineer résumé example

Application Security Engineer résumé example — senior, written for United Kingdom, set in the Plainsong design
Application Security Engineer résumé example, in the Plainsong design

Eight years of security work, each finding written as the thing it stopped rather than the tool that found it.

Written for United Kingdom, at senior, in the software field, shown in the Plainsong design. Every name, employer, address and number below is invented.

Use this example · Browse all 108 résumé examples

Rhys Calderwood — Application Security Engineer

Bristol

Application security engineer with eight years, split between consultancy penetration testing and building security into an insurer engineering programme. Closed an authentication bypass on 240,000 policy accounts within 36 hours of disclosure, and took critical findings at release from 11 to under one.

Experience

Senior Application Security Engineer, Cleeve Mutual · February 2021 – present

Product security for an insurer with 240,000 online policy accounts and 140 repositories.

  • Closed an authentication bypass in the broker portal 36 hours after disclosure, then proved against 14 months of logs that no account had been reached.
  • Built the threat-modelling programme now run on every new service; critical findings at release fell from 11 to under one.
  • Rewrote authorisation around per-object checks, retiring the role-only model behind six of the nine findings in the last external audit.
  • Introduced dependency and secret scanning across 140 repositories, clearing 38 live credentials in the first fortnight.

Security Consultant, Bramwell Security Labs · June 2018 – January 2021

  • Led 40 web and API penetration tests for finance and health clients, two of them under intelligence-led red-team rules.
  • Reported three vulnerabilities in widely used open-source libraries, each assigned a CVE and fixed upstream within a month.
  • Designed the retest process that replaced a full re-engagement, cutting client cost by a third and closing findings a fortnight sooner.

Software Engineer, Tollgate Digital · September 2016 – May 2018

  • Built the payment integration for a ticketing platform taking 70,000 transactions a month, which passed PCI DSS assessment first time.
  • Parameterised queries across 60 endpoints after an injection finding, closing the whole class rather than the single report.

Education

  • BSc Computer Science · Cardiff University · September 2013 – June 2016

Skills

  • Security: Threat modelling, Penetration testing, Secure code review, OWASP ASVS, Incident response
  • Tooling: Burp Suite, Semgrep, Nuclei, Trivy, HashiCorp Vault
  • Engineering: Python, Go, TypeScript, AWS, Terraform, Kubernetes

Certifications

  • Offensive Security Certified Professional — OffSec
  • CREST Registered Penetration Tester — CREST
Loading CVAurum…