David Downey
Senior Security Engineer | CISSP, CCSP, CCSK, and Security + certified with 15 Years of Experience Developing Robust Information Security Operations | Safeguards Networked Endpoints, Data, and Cloud Entities
- Role
- Application Security Engineer at Paycom
- Location
- Dallas-Fort Worth, TX, US
- LinkedIn followers
- 500 followers
About David Downey
As a highly skilled and results-focused security engineer, I have enjoyed being the go-to person, thought-leader, and strategist/tactician within dynamic tech organizations. Advancing across different roles and establishing different security postures to improve systems, I constantly determining what the problem is, what the solution is, and what the vision going forward is, delivering on security needs for companies in a wide variety of industries, including fintech, health care and more. Through strong technical acumen and experience, I excel at developing and implementing information security operations frameworks to ensure control availability, capacity, and performance for users around the world.Central to my skillset is knowing how to work with people. In major companies, I lead, influence, and empower employees through knowledge sharing and robust training practices. Moreover, I deftly respond to customer feedback, including escalations. And, I always seek opportunities where I can relate major technical concepts in an understandable way to non-technical audiences.I am now focused on the next chapter in my career where I can leverage my skills and energy into a senior leadership position in technology management. Please connect with me to have a further conversation!
Experience
Application Security Engineer
Oct 2023 — Present · Grapevine, TX, US
Developing team talent and fulfilling role as a Subject Matter Expert for Vulnerability Management.• Responsible for the development, enforcement and monitoring of security controls, ongoing security hardening of technology assets, and for the delivery of security services.• Boosting the Container Security program using GitLab, Aqua, Artifactory, and similar Kubernetes-related security tools• Proactively architect and improve vulnerability scanning, identification, and risk ranking.• Communicating risks in a meaningful way to business units that may be unfamiliar with security.• Streamlining security scanning for containers by automating SAST, DAST, IaC, secrets, and similar detections.• Keeping up on Information Security threat feeds and security industry tools & trends.• Collaborating with IT, security, risk, legal to ensure full compliance of company policies, procedures, forms, notices, and materials related to Container Security.Select Achievements • Helping CI/CD pipeline developers ‘shift left’ and work to resolve vulnerabilities early in the SDLC.• Automating Dependency Scanning ( & SBOM creation) functions in GitLab via Security Polices and Frameworks• Activating new container security scanning functions to improve the OWASP and CVE findings for developers
Education
University of North Texas
Bachelor of Arts (B.A.), Philosophy
1996 — 1998
Grapevine High School
Honors, AP & Honors Society
1990 — 1994
Skills
- Wireless Networking
- Netcool
- Troubleshooting
- Linux
- Philosophy
- Ipsec Vpn
- Computrace
- Virtualization
- Backtrack
- Firewalls
- Crowdstrike
- Proxim
- Cisco Vpn Concentrator
- Vpn
- Network Security
- Voip
- Data Center
- Mcsa Windows 2003
- Sourcefire
- Ccda
- Qradar
- Comptia Network+ Certified
- Mac Os X Server
- Switches
- Ids
- Unified Communications
- Tcp/Ip
- Cisco Pix & Asa
- Proofpoint
- Disaster Recovery
- Cissp
- Zenoss
- Tropos
- Active Directory
- Windows Server
- Ccna
- Integration
- Enterasys
- Vmware Fusion
- Ccdp
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.