Alejandro Saenz


Self-motivated, results-driven professional with excellent people skills, strong decision making abilities, strong oral and written communication skills, and a high standard of work ethic, seeking a position that promotes learning, encourages innovation, and supports the pursuit of discovery and excellence in the fields of software engineering and application security.

Experience

Staff Product Security Engineer

Twilio Segment
March 2024 - Present

Senior Product Security Engineer

Twilio
  • Designed and developed Snyk Autofactory, an automation framework written in TypeScript and implemented using the Serverless framework. This application seamlessly imports GitHub repositories from over 130 GitHub organizations into Snyk. Additionally, Snyk Autofactory collects Snyk security metrics, automatically archives Snyk projects associated with archived GitHub repositories, and synchronizes Snyk organizations with GitHub organizations. It utilizes AWS services such as Lambda and ECS for efficient execution.
  • Designed and developed the Product Security Metrics Framework (Multivac), empowering security engineers to swiftly develop custom security metrics and seamlessly deploy them on AWS using services such as Lambda and ECS. Additionally, facilitated the creation of security metric dashboards with Snowflake, Tableau, or Domo.
  • Regularly mentor new and current teammates on a weekly basis, providing guidance and support in software development, product security processes, and design reviews. This ensures that any questions are addressed promptly and assists in enhancing their understanding of the subject matter.
September 2022 - March 2024

Product Security Engineer

Twilio Segment
  • Led the security review process for Segment’s Data Purge feature providing clients the ability to protect the privacy and security of customer data and adhere to legislation and privacy regulations. This required organizing and performing multiple threat models in addition to managing security engineers.
  • Upgraded an existing application called Data Inventory to be self-service bridging the gap between data store ownership and engineering teams. The Data Inventory project consisted of a Retool application, a Slack bot, and a security metrics cron job. Each of the components were built with Node.Js. Data Inventory won the “Dino Stomp” award in 2021 during Twilio Segment’s R&D demo day competition. Furthermore, Data Inventory was demoed at the Twilio wide engineering operations review.
  • Assisted in the Threat Model Coverage strategic project where the team and I designed and developed a security metrics framework to determine coverage across Twilio.
  • Assisted in the Singular Security Review (SSR) strategic project where the team and I designed a singular point of entry for all security reviews. SSR compoiled engineering intake and automatically associated the required security teams to the review. Furthermore, SSR utilized a custom JIRA workflow which required collaboration with the internal JIRA development team.
  • Took over Snyk liaison responsibilities for Twilio which required regular interfaces with the Snyk team, assisting engineering with utilizing Snyk, and designing and developing custom Snyk tooling such as building out robust Snyk security metrics.
  • Assisted the Product Security team with operational work such as maintaining and triaging Bugcrowd submissions. This includes validating, triaging, and assigning submissions to the proper engineering team.
  • Demoed around dozen times at the internal Information Security demo days.
July 2021 - September 2022

Senior Application Security Engineer

  • Provides web application static code analysis and dynamic penetration testing
  • Develop application security assessment reporting standards and templates
  • Research and develop internal security tools to optimize team performance
  • Provide application security training including brown bags, lectures, and hands-on laboratories
  • Lead and assist technical interviews for software developer and security candidates
  • Lead developer of Bulwark an organizational asset and vulnerability management tool
September 2019 - July 2021

Senior Software Developer

  • A software development team lead responsible for assuring functional execution of sprint goals
  • Engineer and develop backend implementations, utilizing a microservice architecture, using Node.JS with the Loopback framework.
  • Engineer and develop front-end implementations using Angular 4 with typescript
  • Develop and maintain a web application coding assignment to assist with candidate interviews
  • Lead and assist technical interviews for software developer candidate
  • Perform quarterly static and dynamic web application security assessments
  • Develop application security assessment reporting standards and templates
  • Assist with developer security training
July 2018 - August 2019

Application Security Consultant

  • Engineer and develop front-end implementations of internal tools, including with microservice architectures, using TypeScript, AngularJS, and the latest version of Angular
  • Engineer and develop front-end implementations for a cloud-based IDE using Monaco Editor
  • Perform secure code reviews, web penetration testing, and SDLC consulting
  • R&D for both offensive and defensive security techniques
  • Contribute to open source security projects and collaborate with the broader application security community
  • Contribute to training presentations and coding tutorials for colleagues
November 2015 - July 2018

Software Engineer

  • Played an integral part in the success of the scrum team by developing and delivering user stories
  • Developed a Single Page Application using Java, AngularJS, Bootstrap CSS, and HTML5
  • Provided support for major software development reviews including initial requirements review and preliminary/incremental/critical design reviews
  • Provided support for scrum effort estimation and story points for software release development
  • Assisted with CDRL development on multiple documents including design, development, and peer reviews with a systems engineering team
December 2013 - November 2015

Education

Virginia Commonwealth University

Bachelor of Science
Computer Science
August 2009 - December 2013

Skills

Programming Languages & Tools

Interests

Apart from being an Application Security Engineer and Software developer, I enjoy the outdoors with my wife, son, two daughters, and dog. In the warmer months, my family and I spend the time back country camping, outdoor climbing, hiking, or simply relaxing by the pool. In the colder months, I enjoy watching movies with the family, coding, cooking, and indoor climbing. Additionally, my wife and I love photography! You can see our work below!

https://saenzagphotos.herokuapp.com