jesika@prodsecninja.net | linkedin.com/in/jesikamcevoy
EMBEDDED PRODUCT SECURITY LEADER | THREAT MODELING (STRIDE / EMB3D) | IoT/OT SECURITY
Strategic leader with deep expertise in securing connected product ecosystems. Specialist in harmonizing security governance across the lifecycle of embedded hardware and cloud-native infrastructure. Proven ability to dismantle architectural silos, resolving the inherent friction between device-level communication and cloud-scale defenses to ensure rigorous resilience. Dedicated to driving operational excellence, regulatory compliance, and customer trust in high-velocity, connected markets.
| Product Security Architecture | Compliance Policies & Controls | Operations & Process Improvement |
| Vulnerability & Risk Management | Strategic Program Development | Technical Leadership |
| Penetration Testing & Assessment | Incident Response Programs | Team Development & Mentorship |
| Firmware & Embedded Security | Security Policy & Governance | Industry Thought Leadership |
NOTABLE ACHIEVEMENTS
| “SECURITY BY DESIGN” — Introduced methodology into the product development lifecycle, proactively preventing major architectural flaws and saving years of Engineering effort (Calix). | STREAMLINED PAYMENT ENVIRONMENTS — Simplified and segmented end-to-end payment environments, eliminating redundancies and large batch failures, saving millions in operational costs (Starbucks). |
| COMPLIANCE FRAMEWORK CONSOLIDATION — Aligned policies & controls with ISO 27001, consolidating frameworks into 1 process to improve auditability (SOC 2 Type II, TL-9000), market expansion, and global compliance (Calix). | VULNERABILITY MANAGEMENT INNOVATION — Implemented scalable risk & vulnerability management programs still in operation at major customer businesses across retail, telecom, government, and health care (Rapid7). |
Experience
CALIX, San Jose, CA 2022–2026
Associate Vice President, Cloud & Product Security
- Pioneered a frictionless, global “Security by Design” transformation across the entire system development lifecycle, embedding security architecture, automated CI/CD testing, and cloud observability into a unified, high-velocity pipeline.
- Established a federated ‘Security Champions’ program, empowering cross-functional engineering teams to drive security accountability and customer outreach, ensuring security was intrinsic to the product workflow.
- Directed enterprise security architecture for carrier-grade hardware and cloud management platforms spanning a multi-tenant environment serving thousands of service provider customers, some with over one million subscriber devices. Instituted mandatory threat modeling ahead of code development and manufacturing build specs, applying STRIDE to assess software and infrastructure threats and MITRE EMB3D to assess embedded hardware threats, with every identified countermeasure written directly into design requirements.
- Built and led an in-house Security Operations Center to replace outsourced MSSP services, standing up cloud-native detection and response capabilities and modernizing incident-response practices in alignment with industry-standard threat frameworks.
- Launched a comprehensive Coordinated Vulnerability Disclosure (CVD) program, formalizing policies and external engagement processes to incentivize responsible vulnerability reporting and improve product resilience.
- Reduced Mean Time to Remediation (MTR) by over 90%, achieving 30-day resolution benchmarks and significantly accelerating risk reduction across the product portfolio.
PALO ALTO NETWORKS, Santa Clara, CA 2021–2022
Principal Product Security Architect
- Partnered with product leaders and security champions across the Software Design Lifecycle (SDLC) to identify threats, design secure solutions, and establish repeatable secure design patterns and guidelines for new and existing products.
- Spearheaded the holistic security strategy and architecture for the entire enterprise SASE product suite, seamlessly unifying security controls across cloud-native architectures (Prisma Access), hardware edge gateways (Okyo), SD-WAN infrastructure, and distributed endpoint clients (GlobalProtect).
- Designed scalable, self-service security review workflows that empowered engineering teams to independently assess low-risk changes, freeing the security function to concentrate on high-impact vulnerability detection and remediation oversight.
- Founded employee network group supporting individuals with disabilities or those supporting family members with disabilities
RAPID7, Boston, MA 2013–2021
Principal Security Strategist 2016–2021
- Drove strategic alignment between customer security program needs and the development of innovative security products, leveraging security industry experience to ensure solutions met client requirements.
- Collaborated cross-functionally with Business Development and Pre-Sales teams to define and implement security processes and workflows across operational and technical groups for high-value product initiatives, strategic training programs, and an educational licensing program.
- Delivered high-impact product functionality by advocating for customer needs throughout the product development lifecycle, serving as a liaison, guiding prioritization with Product Managers, and managing risks.
- Analyzed market trends and emerging technology to inform product strategy and guide research and development initiatives.
Managing Consultant 2013–2016
- Developed and implemented program goals and metrics to meet global customer requirements, deploying Rapid7 products into customer environments and creating scripts, dashboards, and custom report templates to address unmet customer needs, driving product improvements that led to the creation of a new role.
- Directed national team of junior and Senior Security Consultants, delivering technical services for on-premises and an evolving suite of SaaS security products; supported pre-sales efforts by collaborating with Sales teams to define scopes, statements of work, and deployment requirements for security solutions.
- Partnered with global clients across diverse industries (e.g., government, retail, telecom, healthcare, hospitality, tourism, education, military, real estate, media, and energy), aligning security products and processes with organizational programs.
GROUP HEALTH COOPERATIVE, Seattle, WA 2012–2013
Sr. Security Specialist, Information Security & Regulatory Compliance
- Developed and implemented processes and standards to identify, assess, and mitigate risks across technology architectures, ensuring robust security controls for sensitive healthcare data.
- Maintained compliance with regulatory requirements and information security best practices, aligning critical systems with organizational and industry standards.
ADDITIONAL ROLES
- T-MOBILE, Bellevue, WA | Senior Security Consultant, Vulnerability Management & Advisory Services | 2011–2012
- STARBUCKS COFFEE COMPANY, Seattle, WA | Senior Security Consultant, PCI Remediation | 2011–2012
- ACCUVANT, Denver, CO | Security Consultant, Penetration Testing | 2007-2009
- HOLLAND AMERICA LINE, Seattle, WA | Information Security Analyst | 2006-2007
- NETIFICE, Seattle, WA | Managed Services Network Engineer | 2005-2006
EDUCATION & CERTIFICATIONS
- Certified Information Systems Security Professional (CISSP), Current
- Bachelor of Applied Arts and Sciences (Network Programming & Organizational Leadership) | University of the Incarnate Word, San Antonio, TX
INDUSTRY IMPACT & SPEAKING ENGAGEMENTS
- ShmooCon: You and Me (But Mostly Me), Building a Product Security Incident Response Program | 2023
- THOTCON/DerbyCon: Overcoming Imposter Syndrome (Even If You’re Totally Faking It) | 2016
- DerbyCon: Putting the “Management” into “Vulnerability Management” | 2015
- ToorCon Seattle: Not Another Boring VoIP Talk: Weaknesses in H.323 Carrier Implementations | 2008
Additional Speaking Engagements: SC Media 20/20 Webcast, InterFace Phoenix, ISACA Seattle and Portland