Michael Carlson
Staff Application Security Engineer - Product Security & Security Strategy - Vulnerability Mgmt, Supply Chain, AI Security
- Role
- Staff Security Engineer at Airtable
- Location
- San Francisco, CA, US
- LinkedIn followers
- 500 followers
About Michael Carlson
Staff Application Security Engineer focused on enabling product teams to ship safely while meeting enterprise risk and compliance expectations. I build scalable security programs (vuln management, supply chain security, AI/LLM governance, secure SDLC automation) and partner with engineering, product, and audit stakeholders to drive clear risk decisions, measurable remediation outcomes, and durable guardrails.
Experience
Staff Security Engineer
Aug 2022 — Present · San Francisco, CA, US
Business partnership- Served as product security partner across multiple high-impact initiatives, translating security risk into practical requirements, mitigations, and delivery plans with engineering and product stakeholders- Drove audit readiness by coordinating cross-team remediation and ensuring vulnerability action items remained within SLA for the annual audit cycle- Authored security risk analyses and RFCs for emerging threat areas (including AI-assisted development risks), aligning stakeholders on prioritized controls and implementation roadmaps.Security platforms & automation- Built and evolved internal security automation platforms to scale AppSec coverage under constrained headcount, improving prioritization quality and reducing manual review burden- Implemented an AI-assisted PR security review system to improve signal-to-noise for security-impactful changes and create an auditable review trail when needed.Software supply chain / compliance- Rolled out software supply-chain malware and dependency-risk scanning across the enterprise, including coverage for AI-generated code paths and third-party ecosystem risks- Delivered an OSS license attribution compliance system using SBOM standards (CycloneDX) and automated workflows to reduce legal/compliance risk and eliminate manual processes.Developer enablement- Replaced legacy onboarding enablement with a modern interactive AppSec training platform (98 interactive modules across ~28 security domains), improving consistency and engineer feedback while removing presenter bottlenecks- Established and operationalized LLM security rules/guardrails to prevent common vulnerability patterns at code generation and review time.
Education
CSU Chico
Business, Information Systems, Management Information Systems Major
California State University, Chico
BS, MIS
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.