Joe Ruwe
Security Architect @F5
Signup · Get unlimited contacts
WORK HISTORY
Security Architect @F5
Technical lead on a Security and Compliance team in a hybrid AWS, GCP and Data Center environment. Collaborates with stakeholders and assigns/performs work in an Agile workflow. Focused on making security part of the Software Development Life Cycle in a DevSecOps methodology. Designs, deploys and manages the operation of multiple security tools, including Hashicorp Vault and a suite of tools that collect data about our environment and send the data to a SIEM (Elasticsearch/Wazuh). Works with engineering teams to design architectures and build proof of concept models for new products and changes to our existing products. Reviews engineering implementations for risks and vulnerabilities, especially in web applications. Implements static code scanning(SAST) tools like Brakeman. Configures and uses Burpsuite, Nessus and Qualys for dynamic/guided testing (DAST). Trains developers on identifying and avoiding common web application vulnerabilities. Uses nmap, Nessus, Qualys, OVAL and other tools to manage vulnerabilities in infrastructure and network architecture. Manages a team of three to organize and present technical and information security risks to executive leadership to facilitate determining organizational risk appetite. Leads efforts to discover, classify, rank and present risks. Maintains a continuous risk registry. Proposes and leads mitigation efforts. Holds periodic meetings to present the risk registry and mitigation efforts. Designed the program by combining NIST 800-37r2 and COSO Risk Management Principles. Developed production middleware in Go and utilities and scripts in Ruby.
EDUCATION
Southeast Community College
Associate of Applied Science, Computer Programming
San Francisco State University
B.A. of Accounting and B.A. of Finance
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.