Patrick Johnson

Principal Security Engineer (Open-Source Security)

Role
Devsecops Sca (Black Duck) Cloud Security Application Security at UnitedHealth Group
Location
Fredericksburg, VA, US
LinkedIn followers
500 followers

About Patrick Johnson

Senior Application Security Engineer with over a decade of expertise in transforming IT environments and enhancing security protocols. Demonstrates a strong command of DevSecOps, cloud architecture, and CI/CD processes, leveraging skills in AWS, Docker, and Jenkins to drive innovation and streamline operations. Passionate about pioneering secure digital transformations and committed to advancing industry best practices in federal and global infrastructures.AWS (Experienced)DevSecOps (Experienced)Cloud Architecture (Experienced)CI/CD (Experienced)Docker (Experienced) Kubernetes (Experienced)Jenkins (Experienced) Puppet (Skillful)Security (Expert) FISMA (Experienced)Infrastructure (Experienced) Drupal (Skillful)Git (Experienced) MySQL (Experienced)PHP (Experienced) AWS CloudFormation (Skillful)Terraform (Experienced) Linux (Experienced)Agile (Experienced) Scrum (Experienced)Python (Skillful)

Experience

  1. Devsecops Sca (Black Duck) Cloud Security Application Security

    UnitedHealth Group

    Jun 2022 — Present · US

    Driven security engineer with extensive experience integrating SCA, SAST, DAST, and automated security workflows into modern CI/CD pipelines across GitHub and Jenkins. I specialize in scaling Black Duck across enterprise DevSecOps programs, enabling continuous vulnerability detection, accurate reporting, SBOM generation, and lifecycle-based risk governance for Java Spring Boot, Python, and C# applications in AWS and hybrid environments.I lead cross-functional initiatives that strengthen enterprise security posture—enhancing vulnerability management through Black Duck API automation, improving visibility of high-risk dependencies, and embedding compliance controls aligned with NIST, ISO 27001, CIS Benchmarks, and UHG internal standards.My work spans secure design reviews, dependency-risk evaluations, threat modeling, IaC and container security assessments, and implementing CI/CD gating policies that drive early risk reduction. I architect advanced DevSecOps frameworks grounded in SSDLC and OWASP SAMM, operationalizing continuous scanning, policy enforcement, automated approvals, and real-time alerts across AWS services (EKS, EC2, API Gateway).I mentor engineering teams on secure coding, remediation workflows, cloud-native security best practices, and rapid incident response—helping to establish a proactive, scalable, and collaborative security-first culture. Passionate about security automation, I deploy and optimize open-source and enterprise security platforms that significantly improve detection capabilities, reduce MTTR, and ensure compliance across all application teams.

Education

  • St. Patrick's High School

    High School Diploma

    1991 — 1994

  • Colorado Technical University

    Master of Business Administration (M.B.A.), Computer/Information Technology Administration and Management

    2015

  • Colorado Technical University

    Bachelor of Science (BSc), Information Technology/Computer Science

    2010 — 2013

  • Colorado Technical University

    Master of Business Administration (M.B.A.), Entrepreneurship/Entrepreneurial Studies

    2014 — 2015

Skills

  • C# 4.0
  • Operating Systems
  • Ip Addressing
  • Unix
  • Windows Server
  • Network Design
  • Mysql
  • IT Operations
  • Ubuntu
  • Php Applications
  • Bash
  • Routers
  • Iptv
  • Firewalls
  • Cable Networks
  • Cisco Technologies
  • Snmp
  • Ethernet
  • Red Hat Linux
  • Solaris
  • Python
  • Network Forensics
  • Jboss Application Server
  • Network Engineering
  • Jquery
  • Unix Shell Scripting
  • Linux Firewalls
  • Apache
  • Shell Scripting
  • Network Security
  • Nagios
  • Network Administration
  • IT Security Policies
  • Computer Forensics
  • Drupal
  • Cable Modems
  • Linux
  • Perl
  • Php
  • Computer Security

Find verified contacts for anyone on LinkedIn

Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.

Free plan included · No credit card required

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.

Patrick Johnson — Devsecops Sca (Black Duck) Cloud Security Application Security at UnitedHealth Group in Fredericksburg, VA, US | Unifers