Marcas Hemmila
Senior Security Engineer @Southern Company
Signup · Get unlimited contacts
WORK HISTORY
Senior Security Engineer @Southern Company
Atlanta, GA, US
Led DevSecOps strategy and execution across a multi-team engineering organization, owning the full security lifecycle from architecture review to production monitoring. My mandate: build the security infrastructure that lets development teams ship fast, without creating new risk.→ Designed and maintained a secure SDLC program integrating Fortify, SonarQube SAST, and Sonatype SCA, WebInspect DAST into CI/CD pipelines, achieving automated security gates on every code merge.→ Partnered with development and operations teams to deploy security tooling across Azure environments using GitHub Actions and PowerShell automation.→ Established vulnerability management processes, from triage and severity classification to remediation SLAs, that brought critical finding resolution time down from 28 days to 3 days.→ Served as security liaison to cross-functional teams, translating complex security requirements into actionable developer guidance that improved first-pass code quality scores.→ Led security architecture reviews for new.NET application deployments, identifying design-level risks before they reached production.Tools & Stack: Fortify · SonarQube · Sonatype · WebInspect · Azure DevOps · GitHub Actions · PowerShell ·.NET · CI/CD Pipeline Security
EDUCATION
University of Arkansas Grantham
Bachelor of Science (BS), Computer Science
Grantham University
associate's degree, Computer Science
Military Tech School
Cable and Antenna Journeyman, Electronic Systems Technology
SKILLS
ABOUT MARCAS HEMMILA
Most security teams are seen as the department of \"no.\" I\'ve spent my career building the opposit, security programs that make engineering teams faster, not slower.I\'m a Senior Security Engineer with deep expertise in application security, vulnerability management, and secure SDLC design. I partner with engineering and product organizations to embed security into development workflows from the start, so teams ship confidently, compliance isn\'t a scramble, and risk is reduced without sacrificing velocity.My approach is equal parts technical and strategic. On the tools side, I\'ve built and managed security pipelines using Fortify, SonarQube, Sonatype, WebInspect, GitHub Actions, and Azure DevOps across enterprise.NET environments. On the program side, I design scalable processes from threat modeling and code review gates to vulnerability triage frameworks, that actually get adopted because they fit how engineering teams work.Across my career, I\'ve led cross-functional security initiatives that reduced vulnerability backlogs, shortened remediation cycles, and helped organizations pass rigorous security assessments without emergency scrambles. I believe the best security program is one developers barely notice, until it saves them from something catastrophic.Currently open to conversations about senior security engineering, DevSecOps leadership, and AppSec architect roles at organizations serious about building security into their SDLC. Areas of expertise: Application Security · DevSecOps · Vulnerability Management · Secure SDLC · CI/CD Security · Security Operations · Risk Management ·.NET Security · ADO · GitHub
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.