Alex Rivera
Application Security Engineer
alex.rivera@email.com·+44 7700 900123·Manchester, UK·linkedin.com/in/alexrivera
Summary
Application security engineer with 6+ years finding and fixing vulnerabilities in web platforms and APIs. Comfortable partnering with product and platform teams to ship secure code without slowing delivery.
Skills
- Burp Suite
- OWASP ASVS
- Python
- threat modeling
- secure code review
- CI/CD security
- AWS
- Kubernetes
Certifications
OSWE (Offensive Security Web Expert)·Offensive Security
2023
Experience
Senior Application Security Engineer·Northwind Security
Remote · EU
2021 – Present
- Led web and API assessments for customer-facing products; reduced critical findings by 40% YoY.
- Built secure SDLC gates in CI (SAST/DAST) and threat modeling for new features.
- Mentored engineers on OWASP ASVS and bug bounty triage.
Penetration Tester·Helix Consulting
London, UK
2018 – 2021
- Delivered external and internal assessments for finance and SaaS clients.
- Authored reproducible reports with clear remediation paths for engineering teams.
Projects
Secure SDLC checklist (internal)
Python, GitHub Actions, Semgrep
- Maintained ASVS-aligned gates and dashboards for 12 product teams.
Education
BSc Computer Science·University of Manchester
2018
Focus: systems security, cryptography
Application security engineer
Classic single-column layout highlighting AppSec programs, SDL, and vuln management.
Use this template