David F.
Principal Security Architect
- Role
- Principal Security Architect at Turbify
- Location
- Portland, OR, US
- LinkedIn followers
- 500 followers
About David F.
Principal Security Architect with 10+ years of experience designing and implementing DevSecOps programs, cloud security architecture, and compliance frameworks across AWS and Azure environments. Deep hands-on expertise in CI/CD security automation, container security, secrets management, vulnerability management, and PCI DSS compliance. Proven ability to lead security initiatives from architecture through implementation, aligning technical strategy with business priorities.
Experience
Principal Security Architect
Jun 2022 — Present · Portland, OR, US
Automated AlmaLinux image builds for AWS and Azure using Packer, Ansible, and Jenkins, integrating LDAP authentication, remote repositories, and monitoring agents for multi-team production adoption• Implemented CIS Level 1 hardened AlmaLinux images using the Red Hat Ansible CIS role, ensuring standardized security baselines across vault infrastructure• Designed and automated Docker image build pipelines using Packer, Ansible, and Jenkins, incorporating vulnerability scanning via Dependency-Track and secure artifact storage in Artifactory• Streamlined Dependency-Track onboarding by automating SBOM generation using Trivy, improving visibility into third-party dependency risks• Developed Jenkins pipelines for automated cloud security scanning across AWS and Azure using Scout Suite, enabling continuous identification of misconfigurations• Built automated ZAP scan pipelines targeting internal applications, integrating DAST into the CI/CD workflow• Led review and update of organizational security policies to achieve PCI DSS compliance• Delivered security architectural reviews and static code analysis across the SDLC, reducing risk prior to production deployments• Safeguarded data via WAF deployment, AWS CloudHSM encryption enforcement, and migration to Azure Key Vault Managed HSM• Onboarded AWS accounts into AWS Organizations and Control Tower to centrally govern multi-account environments• Applied SCPs to enforce compliance guardrails and prevent out-of-policy resource creation• Deployed Alert Logic MDR across all AWS accounts for continuous threat monitoring and alerting
Education
Champlain College
Master of Science - MS, Information Security
2022
Champlain College
Bachelor of Science - BS, Computer Networking
2007
Mercer County Community College
Associate of Applied Science, Network Engineering
2005
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.