Championing Package Vulnerabilities: Leading the integration of package vulnerabilities into Services-db to enhance our Vulnerability Management program and supply chain security.
Technical Lead for OS Package Dependencies: Acted as the technical lead for onboarding OS package dependencies to Services-db, collaborating extensively with the Infra-central + production-excellence teams.
Service-to-Service Communication: Contributed to prototyping the future of service-to-service communication at Shopify via mTLS and Identity signed certificates via SPIFFE in the new infrastructure repository.
Dependency-Analyzer Development: Developed and led the creation of Dependency-Analyzer, a tool for automatically detecting vulnerable packages within Shopify. Created PackageFlagRulesets in Services-db to share analysis with service owners.
Google Cloud Next Representation: Represented Shopify at Google Cloud Next, collaborating with Chronicle and SCC PMs to develop new alerts within the SIEM/SOAR for AWS infrastructure issues.
Clouddo-V3 Development: Developed Clouddo-V3, a Just-in-Time elevated permissions project in Golang, integrating with GCP IAM and Google Workspace groups, and maintained the frontend UI using React/JS.
Sbominator Development: Developed Sbominator, a deep supply chain analysis tool for producing, storing, indexing, and analyzing SBOMs, with a frontend built using React, TypeScript, and GraphQL.
Kubernetes Admission Controllers: Evaluated and championed the onboarding of Kyverno across our entire fleet of clusters, after assessing OPA/Gatekeeper, Kyverno, Chainguard Enforce, and WIZ.
Runtime Security Posture: Maintained runtime security posture using Falco to detect suspicious syscalls, correlating with GCP VPC flow logs, and setting up a test environment for logging and analysis in BigQuery.
Kubernetes/Ingress-NGINX Contributions: Contributed to the open-source project Kubernetes/Ingress-NGINX, implementing features for mTLS and CN validations.
Compliance Team Automation: Assisted the compliance team in automating a manual process using GitHub workflows, saving them several days of work each quarter.
National Assortment Data Analyst
Canadian Tire Corporation
01.2021 - 12.2021
Automated Reporting: Created automated weekly reporting using Python, Task Scheduler, and batch files, saving cross-functional teams an average of 2 hours of work weekly.
Workflow Modernization: Reformed and transferred antiquated Access workflows, rebuilding them with Knime, SQL, and Python scripts, increasing stability and reliability when processing millions of rows of data, and reducing total run time by 5X.
Ad-Hoc Reporting: Created ad-hoc reports using SQL to query and aggregate results from the data warehouse, providing actionable insights for key stakeholders.
Data Transformation: Extracted, transformed, and loaded massive data sets into aggregated and easy-to-consume insights for key stakeholders within the company.
Stakeholder Communication: Communicated and educated a network of 500+ dealers and stakeholders with new and existing reporting to enhance their business performance.