Bj Edward Taduran
Application Security Manager @PSI Software
Signup · Get unlimited contacts
WORK HISTORY
Application Security Manager @PSI Software
DE
Championed the strategic transformation of the Secure Software Development Lifecycle (sSDLC) for a global KRITIS provider. From a legacy \'ground zero\' state, I re-adopted implementation effectively of a lean version of IEC 62•••41 secure SDLC framework across 3 business units and 60+ product lines, aligned to OWASP SAMM maturity structure.Key Achievements:Strategic Leadership: Secured executive buy-in for a modern security roadmap and played a pivotal role in scaling the team by interviewing and building product security teams.Process Optimization: Started reducing tool sprawl by consolidating legacy practices into a high-efficiency stack (GitLab, Trivy, Semgrep), significantly reducing false positives through custom vulnerability tuning.Security Culture Shift: Rebuilt product engineering trust by transitioning security from a \'blocker\' to a centralized support function, replacing unwieldy manual processes with automated security gates.Infrastructure Hardening: Configured, tested, and created baseline for Keycloak, setup and tested nvidia/garak. Among the initiators to eliminate long-lived credentials in config files and introduced standardized guidance for secret management, pipeline security within Gitlab.
EDUCATION
University of the Philippines
Master's degree, Technology Management
University of the Philippines
Bachelor of Science in Applied Mathematics, Actuarial Science
SKILLS
ABOUT BJ EDWARD TADURAN
With a strong foundation in software engineering, DevOps, cloud technologies, and information security, he specialize in building secure, well-architected systems that deliver rapid time to value. He has led agile engineering and security teams, transformed security operations, and advised organizations across public and private sectors in Asia and Europe. His work has focused on securing top fintech companies and digital banks through strategic, risk-based approaches.He has deep experience implementing and aligning with regulatory frameworks including BSP Circular 982, PCI DSS, PSD2, ISO 27001, SOC 2, and GDPR—particularly in high-compliance environments like the FinTech industry.He is a strong advocate for risk-based security governance, believing that policies and processes must be shaped by actual business and threat realities. He regularly present on cybersecurity trends and practices, and one of his long-term goals is to support national-scale security initiatives as a consultant to the Philippine government.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.