Skip to content

American Eagle

Key Dates

Start Date End Date
11/2022 Present

Roles

  • Senior Security Analyst

Responsibilities

  • Led Cloud Security strategy across a $5B+ retail enterprise through architecture and operational support.
    • Created VPC Service Controls and Custom Org Policies to provide preventative security controls.
    • Migrated 85+ groups containing 750+ users from standard to privileged accounts, implementing zero trust IAM controls to fortify our GCP environment against SSO compromise.
    • Defined and implemented Cloud Security standards on a GCP platform of over 500+ projects.
  • Architected and operationalized enterprise Wiz CNAPP platform deployment and ongoing support.
    • Migrated Prisma CSPM to Wiz while ensuring all alerts / logs / resources successfully mapped.
    • Enforced 225+ daily container image scans to utilize Wizcli, blocking builds with security violations.
    • Integrated runtime sensor into 40+ Kubernetes clusters in an automated manner via helm chart.
    • Built 100+ high-fidelity custom detections to alert on threats mapped to the MITRE ATT&CK framework.
  • Owned AI security strategy to proactively protect company assets, aligned to OWASP Top 10 for LLMs principles.
    • Evaluated Palo AIRS runtime AI security platform to mitigate prompt injection and model/data leakage.
    • Hardened Cursor platform for 700+ users: extension controls, configuration hardening, MCP allowlisting.
    • Developed an MCP integration review process and published this into an official company standard.
  • Managed Akamai WAF/Bot/API security configuration for AE.com, protecting 18M+ monthly users from web application attacks and malicious bot traffic.
  • Implemented security standards and controls on a Google Workspace environment supporting over 3000+ users.
    • Exported Drive metadata into BigQuery to automate visibility and reporting of externally shared files.
    • Developed a Third Party integration review process and published this into an official company standard.
  • Implemented controls within JFrog artifact repository to protect against software supply chain attacks.
  • Drove security architecture reviews across teams, embedding secure-by-design principles into new initiatives.
  • Led enterprise-wide incident response investigations spanning triage, containment, and root cause analysis.