Dave Ferguson

Director of Technical Product Management, Software Supply Chain Security @ReversingLabs

Dallas-Fort Worth, TX, US
MOBILE NUMBERS
+91 *********19

Signup · Get unlimited contacts

WORK HISTORY

Apr 2023 — Present

Director of Technical Product Management, Software Supply Chain Security @ReversingLabs

View department →

Dallas-Fort Worth, TX, US

As a PM for Spectra Assure, I help build solutions for Product Security and DevOps teams to ensure their releases are safe and free of undesirable things like malware, tampering, vulnerabilities, stored secrets, and backdoors. The bottom line? As a publisher of software, you don\'t want to inadvertently be the source of a supply chain attack and infect your paying customers. Advanced, nation-state threat actors are focused exactly on that. Ask me about differential analysis and reproducible builds. They are effective countermeasures.

EDUCATION

N/A

The University of Kansas

Master of Science, Mechanical Engineering

N/A

The University of Kansas

Bachelor of Science, Aerospace Engineering

SKILLS

Software DevelopmentApplication SecurityWeb Application SecurityInformation SecuritySecure CodingJavaOwaspSecure SdlcInternet SecurityComputer SecurityCisspCsslpCode ReviewPenetration TestingCloud ComputingMobile SecurityInformation Security ManagementSecurityEnterprise SoftwarePayment Card Industry Data Security Standard (Pci Dss)Threat ModelingWeb ApplicationsVulnerability Assessment

ABOUT DAVE FERGUSON

Seasoned Application Security & Product Management professional with broad range of experience covering 20 years in cybersecurity and 10+ years as a developer prior to that. Highly technical with exceptional communication skills for all types of audiences and ability to drive results. Highlights:* Built the initial AppSec program at a $3 billion travel technology company.* Expert-level knowledge in SAST, DAST, SCA, web app pen testing, and developer training.* Director & Product Manager for a dynamic scanning (DAST) product with >$30m ARR* Hold CISSP and CSSLP certifications from (ISC)2 since 2005 and 2009, respectively.* Reported major CSRF vulnerabilities in the Netflix website, one of the first highly-publicized instances of cross-site request forgery on the Web.* Credited with discovery of CVE-20••••63 and CVE-20••••37.* Original author of the OWASP Forgot Password Cheat Sheet.* Former PCI QSA and PA-QSA for FishNet Security (now Optiv).

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.