> whoami

Senior Product Security Engineer

Building secure software at enterprise scale. DevSecOps programs, AppSec tooling, cloud security, and connected-device security.

Dallas, TX OSCP Certified 13+ Years Experience
60%
Vuln Reduction
75%
Compliance Automated
3000h
Saved Annually
Get In Touch
andriy@a3sec: ~ type help

What I Deliver

Available for contract work: fixed-price audits and implementations, or retainers. Remote (US Central) or on site in Dallas–Fort Worth.

DevSecOps

  • CI/CD security gates
  • Policy-as-code guardrails
  • IaC security scanning
  • Pipeline hardening

AppSec Programs

  • SAST/DAST/SCA rollouts
  • Secure SDLC frameworks
  • Threat modeling
  • AI/LLM red teaming
  • AI agent & MCP server reviews
  • Gen-AI security automation

Cloud Security

  • AWS/GCP hardening
  • CIS benchmark implementation
  • Multi-account strategy
  • Runtime protection

Device & Mobile Security

  • Smart TV & embedded platform testing
  • Android application security
  • Connected-device security monitoring
  • Incident response & forensics

Selected Work

Vulnerability Management Program

60% reduction

Partnered with 8+ product teams to embed secure-by-design requirements throughout the SDLC and drive a risk-based vulnerability management program across cloud and on-prem estates.

  • Integrated Snyk, Tenable, Orca, and Armis with CI/CD pipelines
  • Reduced critical vulnerability backlog by 60% in two quarters
  • Implemented policy-as-code guardrails cutting review time from days to under 30 minutes
  • Hardened multi-cloud environments (AWS & GCP) using Terraform and CIS benchmarks
Snyk Tenable Orca Terraform AWS GCP

LLM-Powered Compliance Bot

75% effort saved

Designed and built a RAG-powered Slack bot that automates compliance evidence collection, intelligent report generation, and real-time security alerting.

  • Built RAG pipeline for intelligent compliance querying and report generation
  • Developed interactive Slack bot with LLM-powered natural language interface
  • Integrated with Asana for automated remediation task tracking
  • Leveraged AWS Athena to analyze CloudTrail logs and surface anomalies
  • Reduced manual compliance effort by 75%
Python LLM/RAG Slack API Asana API AWS Athena CloudTrail

Enterprise SAST/DAST Rollout

120+ engineers

Led enterprise-wide security tooling deployment for a medical IoT platform, enabling secure development practices at scale.

  • Led SonarQube Enterprise rollout with Terraform HA cluster and CI/CD integration
  • Deployed Burp Suite Enterprise with pipeline hooks and DAST triage training
  • Enabled 120+ engineers through developer security training sessions
  • Achieved 85% DAST scan coverage across 30 repositories
SonarQube Burp Suite Terraform Jenkins GitLab

Platform Security Automation

40% to 90% compliance

Enhanced security automation for a cloud-native software-defined networking platform delivering managed services to enterprise customers.

  • Integrated Black Duck for container and application SCA
  • Developed security tools for CI/CD pipeline integration
  • Established automated security testing frameworks
  • Improved release compliance from 40% to 90%
Black Duck CI/CD Container Security Python

ShakerScan

open source

Personal open-source project (AGPL-3.0): a security testing platform for web apps, APIs, AI systems and connected devices, self-hosted in Docker with a web UI, REST API and CLI, and built to be driven by an AI coding agent in plain English.

  • Scan: repeatable DAST from a quick posture check to authorized active XSS/SQLi testing; Hunt: AI-assisted investigation using your own Codex, Claude Code or OpenCode session, with scope, budgets and evidence managed by the platform
  • AI Gate tests for chat, RAG, agent and MCP endpoints; Model Intake checks for model artifacts; continuous attack-surface monitoring; connected-device posture for TVs, cameras, printers and routers
  • One-line Docker install, Homebrew tap, Fleet workers for distributed execution; Enterprise edition adds SSO, roles and audit logging
  • Source and docs: github.com/andriyze/shakerscan · shakerscan.com
Python TypeScript Docker Redis PostgreSQL Nuclei

This site

live demo

a3sec.net is its own case study: everything below is built and running here, all of it managed in Terraform.

  • Static site on S3 behind CloudFront with Origin Access Control: no public bucket, no website endpoint, all of it in Terraform.
  • Security headers and a CSP enforced at the edge, with a hash-based CSP on the calculator pages.
  • A self-healing cost circuit breaker: one-minute CloudFront alarms, automatic restore, a budget scoped to the site's own services.
  • A public JSON API and MCP server on Lambda with input validation, rate limits, origin validation and tests.
  • Honeypot paths armed with Canarytokens, and a public traffic dashboard built from access logs that publishes aggregates only.
  • Everything readable without JavaScript and documented for agents in llms.txt.
  • Try it: type help in the terminal above, call /api, or point an MCP client at https://www.a3sec.net/api/mcp
AWS Terraform CloudFront Lambda MCP

SEC101

free course

An interactive course on everyday cybersecurity for non-specialists, in Ukrainian: the habits and settings that stop most real-world attacks.

  • Modules on passwords and managers, MFA, phishing, browser privacy, device hygiene, safe tools, and networking basics
  • Hands-on checks and quizzes instead of slides, so readers verify their own setup as they go
  • Live at sec101.a3sec.net
Security awareness Education Ukrainian

Experience

2026 - Present
Senior Security Engineer
  • Building security monitoring for smart TV platforms and companion Android apps
  • Lead threat modeling and security design reviews for TV platform and mobile features
  • Hands-on smart TV and Android app testing with Burp Suite Enterprise
  • Automated vulnerability management across Tenable, Nexpose, Wiz, SonarQube, and GitHub Advanced Security
  • Incident response, forensics, and AWS/GCP hardening, with AI tooling to speed up triage
2023 - 2026
Senior Product Security Engineer
  • Reduced critical vulnerability backlog 60% via CI/CD tool integration
  • Policy-as-code guardrails cut security reviews from days to 30 minutes
  • Built RAG-powered compliance bot reducing manual audit work by 75%
  • Implemented LLM-based security triage and vulnerability analysis
2021 - 2022
Senior DevSecOps Engineer
  • Enterprise SonarQube and Burp Suite rollout for 120+ engineers
  • Achieved 85% DAST scan coverage across application portfolio
  • AWS and web/API security assessments
2020 - 2021
Security Automation Engineer
  • Black Duck SCA integration for container security
  • Release compliance improved from 40% to 90%
  • CI/CD security gate implementation
2013 - 2020
QA & Test Automation Engineer
  • Built test automation frameworks (Selenium, Python, TypeScript)
  • Vulnerability assessments and internal penetration testing
  • CI/CD pipeline configuration and containerized testing

Tech Stack

Security Tooling

Snyk Tenable Nexpose (Rapid7) Wiz Orca Security SonarQube GitHub Advanced Security Burp Suite Enterprise Armis Black Duck Qualys

Cloud & Infrastructure

AWS GCP Terraform Docker Kubernetes

Languages & Automation

Python TypeScript GitHub Actions Jenkins GitLab CI Bash

AI & LLM Engineering

Claude Code OpenAI Codex RAG Pipelines LLM Security Triage AI Red Teaming MCP Servers Prompt Injection Research

Frameworks & Standards

OWASP Top 10 OWASP ASVS BSIMM SAMM NIST

Certifications

OSCP

Offensive Security Certified Professional

CEH

Certified Ethical Hacker

ISTQB

Certified Tester

Live traffic

Who is hitting this site, aggregated hourly from the CloudFront access logs: real visitors, vulnerability scanners probing for WordPress and .env files, AI crawlers, and countries blocked at the edge. Only counts are published, never addresses.

Countries (7 days)

Top pages (7 days)

Scanner probes by type (7 days)

AI crawlers (7 days)

AI assistant referrals (7 days)

Visitors by kind (7 days, distinct IPs)

Edge locations (7 days)

Blocked at the edge (7 days)

What this page can see about you

Everything below is read in your browser with ordinary web APIs, the same ones ad networks combine into a fingerprint. Your IP address and approximate location come from the CloudFront edge that served this page, not from a third party. Nothing is stored or sent anywhere else.

Try it again in a private window, over a VPN, or with a fingerprinting blocker and see what changes.

Let's Talk Security

Andriy Zelenyuk, available for contract work: security audits, AppSec and cloud implementations, automation, and AI-agent reviews. Remote or on site in Dallas–Fort Worth; fixed price or retainer, quoted after a 30-minute call.

contact@a3sec.net
Dallas, TX LinkedIn GitHub PGP Key