Brandon Lum
Software Engineer, GOSST
- Role
- Open Source Security Engineer at Google
- Location
- New York, NY, US
- LinkedIn followers
- 500 followers
About Brandon Lum
I design and implement computer systems, with a focus on Security, Operating Systems, and Distributed/Parallel Systems. I enjoy tackling both technical and business challenges and have a side interest in organizational behavior and leadership.Brandon loves designing and implementing computer systems (with a focus on Security, Operating Systems, and Distributed/Parallel Systems). Brandon is Co-chair Emeritus of the CNCF Security TAG, and as a part of Google’s Open Source Security and BCID team, he works on improving the security of the Open Source ecosystem and observability into all of Google\'s software supply chain metadata (SBOMs, SLSA, etc.). Previously at IBM Research, Brandon worked on various security areas such as: Container content protection via encryption and image signing, identity, and kernel attack surface reduction.
Experience
Open Source Security Engineer
Jan 2022 — Present · NY, US
Led Google\'s Software Supply Chain Inventory and SBOM portfolio, which drove horizontal security programs, board risk reporting and helped teams achieve security compliance- Drove Google’s SBOM implementation for EO 14028 compliance as an SME in SBOMs, establishing direction on how SBOMs are generated, cataloged, composed, and retrieved, writing policy/guidance for SBOM use and compliance- Led initiatives to drive scalable (>400M SBOMs, 2M+ SBOMs/day, 1B+ artifacts) use of Google SBOM/SLSA and software inventory (SCILo), helping product teams (e.g. Cloud, Android, etc.) drive compliance and improve board risk metrics through Google’s Software Supply Chain Integrity (SSCI) program- Founded the GUAC project and community, an initiative for aggregating and synthesizing supply chain metadata, growing it to 200+ members across 100+ companies (Google, Microsoft, Yahoo, RedHat, etc.), accepted into the OpenSSF as an incubating project and growing with the acquisition of RedHat trustify project/product- Chaired and created the SPDX Build Working Group, collaborating with industry leaders (VMWare, IBM, Microsoft, Cisco) to develop the SPDX 3.0 spec build profile and maintainer of OpenVEX, a Vulnerability Exploitability eXchange standard integrated into major vulnerability scanners (Grype, Trivy, govulncheck).
Education
Temasek Polytechnic
Diploma, Cyber & Digital Security
2007 — 2010
Carnegie Mellon University
Undergraduate, Computer Science
2012 — 2016
Skills
- Application Security
- Web Application Security
- Computer Forensics
- System Administration
- Security
- Iso 27001
- Penetration Testing
- Operating Systems
- Computer Security
- Pci Dss
- Information Security
- Security Audits
- IT Audit
- Open Source
- Firewalls
- Cryptography
- Information Security Management
- Malware Analysis
- Software Development
- Linux
- Network Security
- Vulnerability Assessment
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.