25,000+ applications secured
Drove adoption of a modular security suite across Disney's enterprise portfolio.
The Walt Disney CompanyRoman Romanenco
Enterprise security programs that engineering teams actually adopt, without trading velocity for safety.
See the results
About
Most programs slow companies down because they're built like compliance checklists, not products. I've spent a decade building the opposite, turning security from a gate into a platform.
Every control, integration, and policy gets treated as a product: users, feedback loops, a shipping cadence. That's why the programs I lead get adopted instead of avoided. Currently doing that across the Disney portfolio, backed by an MBA from UT McCombs and a decade of hands-on technical depth.
I learned that operating tempo matters early, as a U.S. Marine.
I'll review your request and send the latest version to your email. See how this data is handled.
Check your email within 24 hours.
Where I've worked




Impact
Measurable outcomes across enterprise security and product.
Drove adoption of a modular security suite across Disney's enterprise portfolio.
The Walt Disney CompanyBuilt and launched Hulu's responsible disclosure program — 370+ vulnerabilities found, $270K in bounties.
HuluManaged Yahoo's bug bounty lifecycle to the platform's top-ranked program globally.
YahooShipped Terraform-based infrastructure automation for security tooling across dozens of AWS accounts.
The Walt Disney CompanyLed security assessments that remediated 100+ vulnerabilities and unlocked pursuit of $10M+ in federal opportunities.
Booz Allen HamiltonDesigned the strategy to unify product security across Disney's business units post-reorg, reducing tooling redundancy and establishing a single operating model.
The Walt Disney CompanyEducation
Explore
Ideas on product security, and tools I've open-sourced.
I spent years finding critical vulnerabilities. Then I realized finding them wasn't the hard part.
May 22, 2026Most teams confuse a list of features with a strategy. Here's the 6-step framework I use to build product strategies that actually hold up under pressure.
Sep 6, 2023Unified inventory for source code management platforms. Aggregates from GitHub, GitLab, and beyond, with intelligence on languages, structure, and metadata.
Automated creation of hardened, deployment-ready Kali Linux AMIs for red team operations and penetration testing in AWS.
Contact me
If you're building enterprise security as a product capability, evaluating AppSec tooling and strategy, or hiring for product security leadership, reach out. I read every message.