Senior Product Security Engineer
Building secure software at enterprise scale. DevSecOps programs, AppSec tooling, cloud security, and connected-device security.
What I Deliver
Available for contract work: fixed-price audits and implementations, or retainers. Remote (US Central) or on site in Dallas–Fort Worth.
DevSecOps
- CI/CD security gates
- Policy-as-code guardrails
- IaC security scanning
- Pipeline hardening
AppSec Programs
- SAST/DAST/SCA rollouts
- Secure SDLC frameworks
- Threat modeling
- AI/LLM red teaming
- AI agent & MCP server reviews
- Gen-AI security automation
Cloud Security
- AWS/GCP hardening
- CIS benchmark implementation
- Multi-account strategy
- Runtime protection
Device & Mobile Security
- Smart TV & embedded platform testing
- Android application security
- Connected-device security monitoring
- Incident response & forensics
Selected Work
Vulnerability Management Program
60% reduction
Vulnerability Management Program
60% reductionPartnered with 8+ product teams to embed secure-by-design requirements throughout the SDLC and drive a risk-based vulnerability management program across cloud and on-prem estates.
- Integrated Snyk, Tenable, Orca, and Armis with CI/CD pipelines
- Reduced critical vulnerability backlog by 60% in two quarters
- Implemented policy-as-code guardrails cutting review time from days to under 30 minutes
- Hardened multi-cloud environments (AWS & GCP) using Terraform and CIS benchmarks
LLM-Powered Compliance Bot
75% effort saved
LLM-Powered Compliance Bot
75% effort savedDesigned and built a RAG-powered Slack bot that automates compliance evidence collection, intelligent report generation, and real-time security alerting.
- Built RAG pipeline for intelligent compliance querying and report generation
- Developed interactive Slack bot with LLM-powered natural language interface
- Integrated with Asana for automated remediation task tracking
- Leveraged AWS Athena to analyze CloudTrail logs and surface anomalies
- Reduced manual compliance effort by 75%
Enterprise SAST/DAST Rollout
120+ engineers
Enterprise SAST/DAST Rollout
120+ engineersLed enterprise-wide security tooling deployment for a medical IoT platform, enabling secure development practices at scale.
- Led SonarQube Enterprise rollout with Terraform HA cluster and CI/CD integration
- Deployed Burp Suite Enterprise with pipeline hooks and DAST triage training
- Enabled 120+ engineers through developer security training sessions
- Achieved 85% DAST scan coverage across 30 repositories
Platform Security Automation
40% to 90% compliance
Platform Security Automation
40% to 90% complianceEnhanced security automation for a cloud-native software-defined networking platform delivering managed services to enterprise customers.
- Integrated Black Duck for container and application SCA
- Developed security tools for CI/CD pipeline integration
- Established automated security testing frameworks
- Improved release compliance from 40% to 90%
ShakerScan
open source
ShakerScan
open sourcePersonal open-source project (AGPL-3.0): a security testing platform for web apps, APIs, AI systems and connected devices, self-hosted in Docker with a web UI, REST API and CLI, and built to be driven by an AI coding agent in plain English.
- Scan: repeatable DAST from a quick posture check to authorized active XSS/SQLi testing; Hunt: AI-assisted investigation using your own Codex, Claude Code or OpenCode session, with scope, budgets and evidence managed by the platform
- AI Gate tests for chat, RAG, agent and MCP endpoints; Model Intake checks for model artifacts; continuous attack-surface monitoring; connected-device posture for TVs, cameras, printers and routers
- One-line Docker install, Homebrew tap, Fleet workers for distributed execution; Enterprise edition adds SSO, roles and audit logging
- Source and docs: github.com/andriyze/shakerscan · shakerscan.com
This site
live demo
This site
live demoa3sec.net is its own case study: everything below is built and running here, all of it managed in Terraform.
- Static site on S3 behind CloudFront with Origin Access Control: no public bucket, no website endpoint, all of it in Terraform.
- Security headers and a CSP enforced at the edge, with a hash-based CSP on the calculator pages.
- A self-healing cost circuit breaker: one-minute CloudFront alarms, automatic restore, a budget scoped to the site's own services.
- A public JSON API and MCP server on Lambda with input validation, rate limits, origin validation and tests.
- Honeypot paths armed with Canarytokens, and a public traffic dashboard built from access logs that publishes aggregates only.
- Everything readable without JavaScript and documented for agents in llms.txt.
- Try it: type
helpin the terminal above, call /api, or point an MCP client athttps://www.a3sec.net/api/mcp
SEC101
free course
SEC101
free courseAn interactive course on everyday cybersecurity for non-specialists, in Ukrainian: the habits and settings that stop most real-world attacks.
- Modules on passwords and managers, MFA, phishing, browser privacy, device hygiene, safe tools, and networking basics
- Hands-on checks and quizzes instead of slides, so readers verify their own setup as they go
- Live at sec101.a3sec.net
Experience
- Building security monitoring for smart TV platforms and companion Android apps
- Lead threat modeling and security design reviews for TV platform and mobile features
- Hands-on smart TV and Android app testing with Burp Suite Enterprise
- Automated vulnerability management across Tenable, Nexpose, Wiz, SonarQube, and GitHub Advanced Security
- Incident response, forensics, and AWS/GCP hardening, with AI tooling to speed up triage
- Reduced critical vulnerability backlog 60% via CI/CD tool integration
- Policy-as-code guardrails cut security reviews from days to 30 minutes
- Built RAG-powered compliance bot reducing manual audit work by 75%
- Implemented LLM-based security triage and vulnerability analysis
- Enterprise SonarQube and Burp Suite rollout for 120+ engineers
- Achieved 85% DAST scan coverage across application portfolio
- AWS and web/API security assessments
- Black Duck SCA integration for container security
- Release compliance improved from 40% to 90%
- CI/CD security gate implementation
- Built test automation frameworks (Selenium, Python, TypeScript)
- Vulnerability assessments and internal penetration testing
- CI/CD pipeline configuration and containerized testing
Tech Stack
Security Tooling
Cloud & Infrastructure
Languages & Automation
AI & LLM Engineering
Frameworks & Standards
Certifications
OSCP
Offensive Security Certified Professional
CEH
Certified Ethical Hacker
ISTQB
Certified Tester
Live traffic
Who is hitting this site, aggregated hourly from the CloudFront access logs: real visitors, vulnerability scanners probing for WordPress and .env files, AI crawlers, and countries blocked at the edge. Only counts are published, never addresses.
Countries (7 days)
Top pages (7 days)
Scanner probes by type (7 days)
AI crawlers (7 days)
AI assistant referrals (7 days)
Visitors by kind (7 days, distinct IPs)
Edge locations (7 days)
Blocked at the edge (7 days)
What this page can see about you
Everything below is read in your browser with ordinary web APIs, the same ones ad networks combine into a fingerprint. Your IP address and approximate location come from the CloudFront edge that served this page, not from a third party. Nothing is stored or sent anywhere else.
Let's Talk Security
Andriy Zelenyuk, available for contract work: security audits, AppSec and cloud implementations, automation, and AI-agent reviews. Remote or on site in Dallas–Fort Worth; fixed price or retainer, quoted after a 30-minute call.
contact@a3sec.net