Experience
Roles across application security, backend engineering, and identity-focused platform work — with emphasis on OAuth2/OIDC, APIs, and secure delivery.
Application Security Engineer
RxBenefits — Birmingham, AL
July 2025 – Present
- Led application security efforts across internally developed services and APIs, partnering directly with engineering teams to identify and remediate vulnerabilities early in the SDLC.
- Implemented and operationalized Snyk for SAST, dependency, and container scanning, integrating findings into GitHub workflows and Jira-based remediation processes.
- Established risk-based vulnerability triage processes, prioritizing remediation based on exploitability, data sensitivity, and business impact.
- Conduct secure design and code reviews, providing actionable guidance aligned with OWASP Top 10 and API Security Top 10.
- Act as a security advisor to development teams, improving secure coding practices and reducing repeat vulnerability patterns across services.
Software Engineer II
RxBenefits — Birmingham, AL
January 2024 – July 2025
- Led backend development of a custom API Gateway microservice in Go to mediate traffic between distributed systems.
- Integrated Auth0 for OAuth 2.0 authentication and authorization with custom RBAC validation logic.
- Designed and implemented secure JWT claim injection using Node.js serverless functions (Auth0 Actions).
- Worked across languages and SaaS tools to deliver cohesive portal experiences tailored to distinct authenticated audiences.
- Contributed to SCIM-based provisioning workflows to automate identity synchronization with third-party applications.
- Developed Dockerized PostgreSQL services for user permissions and access logs.
Software Engineer
RxBenefits — Birmingham, AL
January 2023 – January 2024
- Built custom REST APIs with validation, routing, OpenAPI docs, database migrations, and Helm configuration.
- Refactored services for performance and expanded AWS usage, including EventBridge-triggered Lambda jobs.
- Contributed to frontend work with Next.js and React.
Security Administrator
RxBenefits — Birmingham, AL
January 2021 – December 2022
- Built PowerShell and Python automation for user lifecycle, workstation decommissioning, and SOC 2 auditing, using AWS Lambda where appropriate.
- Led Keeper Password Manager rollout: POC, SSO, Azure SCIM provisioning/deprovisioning, RBAC, and MFA-based device approval.
- Improved vulnerability tracking and remediation workflows in Jira.
Education
CompTIA Security+ certification