Zachary Hickman
AppSec Engineer | Vulnerability Management Proactive SDLC Security: Leveraging a 15-year enterprise development background to engineer automated vulnerability pipelines that neutralize threats long before production.

Summary

An engineering-driven security leader specializing in the comprehensive defense of complex, multi-cloud environments. My focus is translating security and compliance requirements into programmatic controls embedded directly within the SDLC. From building enterprise scanning ecosystems to custom Python automation, I deliver pragmatic security solutions that systematically reduce risk without compromising deployment velocity.


Technical Expertise

Enterprise Application Security & SDLC

  • AppSec Initiatives: Leading program management for large-scale environments, including secure coding standards, threat modeling, and code review automation.
  • DevSecOps Integration: Embedding automated security tooling (SAST/DAST/SCA) directly into CI/CD pipelines to create efficient guardrails.
  • Secure-by-Design: Aligning software engineering teams with web application security standards (OWASP Top 10) and least-privilege architecture.

Vulnerability Management & Pipeline Engineering

  • Orchestration: Designing continuous scanning, validation, and prioritization pipelines across complex corporate ecosystems.
  • Platform Administration: Serving as primary architect for enterprise vulnerability management suites (Nessus, Tenable.sc, Tenable VM, Cloud, and IoT).
  • Workflow Automation: Engineering custom scripts and integrations (Python, PowerShell, SQL, REST APIs) to automate triage, reporting, and ticketing.

SIEM, Analytics & Detection Engineering

  • Operational Intelligence: Transforming raw security telemetry into actionable, prioritized operational data.
  • Detection Tuning: Developing and refining detection logic and alert filtering inside SIEM/SOAR solutions, Splunk, and ELK Stack environments.
  • Security Business Intelligence: Building centralized data models and interactive dashboards for compliance and exposure tracking.

Hybrid & Cloud-Native Security

  • Workload Hardening: Leveraging infrastructure engineering experience to secure modern, distributed workloads.
  • Cloud Architecture: Hardening infrastructure across Azure, AWS, GCP, and Oracle Cloud environments.
  • Containerization & Config: Securing containerized workloads (Docker) and microservices, and utilizing Infrastructure as Code (Ansible/YAML).