Jesika L. McEvoy      

jesika@prodsecninja.net | linkedin.com/in/jesikamcevoy

EMBEDDED PRODUCT SECURITY LEADER |  THREAT MODELING (STRIDE / EMB3D)  |  IoT/OT SECURITY 

Strategic leader with deep expertise in securing connected product ecosystems. Specialist in harmonizing security governance across the lifecycle of embedded hardware and cloud-native infrastructure. Proven ability to dismantle architectural silos, resolving the inherent friction between device-level communication and cloud-scale defenses to ensure rigorous resilience. Dedicated to driving operational excellence, regulatory compliance, and customer trust in high-velocity, connected markets.

Product Security ArchitectureCompliance Policies & Controls Operations & Process Improvement
Vulnerability & Risk Management Strategic Program DevelopmentTechnical Leadership
Penetration Testing & AssessmentIncident Response ProgramsTeam Development & Mentorship
Firmware & Embedded SecuritySecurity Policy & GovernanceIndustry Thought Leadership

NOTABLE ACHIEVEMENTS

“SECURITY BY DESIGN” — Introduced methodology into the
product development lifecycle, proactively preventing major
architectural flaws and saving years of Engineering effort (Calix).
STREAMLINED PAYMENT ENVIRONMENTS —
Simplified and segmented end-to-end payment
environments, eliminating redundancies and large batch
failures, saving millions in operational costs (Starbucks).
COMPLIANCE FRAMEWORK CONSOLIDATION —
Aligned policies & controls with ISO 27001, consolidating
frameworks into 1 process to improve auditability (SOC 2 Type
II, TL-9000), market expansion, and global compliance (Calix).
VULNERABILITY MANAGEMENT INNOVATION —
Implemented scalable risk & vulnerability management
programs still in operation at major customer businesses
across retail, telecom, government, and health care (Rapid7).

Experience

CALIX, San Jose, CA       2022–2026

Associate Vice President, Cloud & Product Security 

  • Pioneered a frictionless, global “Security by Design” transformation across the entire system development lifecycle, embedding security architecture, automated CI/CD testing, and cloud observability into a unified, high-velocity pipeline.
  • Established a federated ‘Security Champions’ program, empowering cross-functional engineering teams to drive security accountability and customer outreach, ensuring security was intrinsic to the product workflow.
  • Directed enterprise security architecture for carrier-grade hardware and cloud management platforms spanning a multi-tenant environment serving thousands of service provider customers, some with over one million subscriber devices. Instituted mandatory threat modeling ahead of code development and manufacturing build specs, applying STRIDE to assess software and infrastructure threats and MITRE EMB3D to assess embedded hardware threats, with every identified countermeasure written directly into design requirements.
  • Built and led an in-house Security Operations Center to replace outsourced MSSP services, standing up cloud-native detection and response capabilities and modernizing incident-response practices in alignment with industry-standard threat frameworks.
  • Launched a comprehensive Coordinated Vulnerability Disclosure (CVD) program, formalizing policies and external engagement processes to incentivize responsible vulnerability reporting and improve product resilience.
  • Reduced Mean Time to Remediation (MTR) by over 90%, achieving 30-day resolution benchmarks and significantly accelerating risk reduction across the product portfolio.

PALO ALTO NETWORKS, Santa Clara, CA             2021–2022

Principal Product Security Architect 

  • Partnered with product leaders and security champions across the Software Design Lifecycle (SDLC) to identify threats, design secure solutions, and establish repeatable secure design patterns and guidelines for new and existing products.
  • Spearheaded the holistic security strategy and architecture for the entire enterprise SASE product suite, seamlessly unifying security controls across cloud-native architectures (Prisma Access), hardware edge gateways (Okyo), SD-WAN infrastructure, and distributed endpoint clients (GlobalProtect).
  • Designed scalable, self-service security review workflows that empowered engineering teams to independently assess low-risk changes, freeing the security function to concentrate on high-impact vulnerability detection and remediation oversight.
  • Founded employee network group supporting individuals with disabilities or those supporting family members with disabilities

RAPID7, Boston, MA             2013–2021

Principal Security Strategist             2016–2021

  • Drove strategic alignment between customer security program needs and the development of innovative security products, leveraging security industry experience to ensure solutions met client requirements.
  • Collaborated cross-functionally with Business Development and Pre-Sales teams to define and implement security processes and workflows across operational and technical groups for high-value product initiatives, strategic training programs, and an educational licensing program.
  • Delivered high-impact product functionality by advocating for customer needs throughout the product development lifecycle, serving as a liaison, guiding prioritization with Product Managers, and managing risks.
  • Analyzed market trends and emerging technology to inform product strategy and guide research and development initiatives.

Managing Consultant               2013–2016

  • Developed and implemented program goals and metrics to meet global customer requirements, deploying Rapid7 products into customer environments and creating scripts, dashboards, and custom report templates to address unmet customer needs, driving product improvements that led to the creation of a new role.
  • Directed national team of junior and Senior Security Consultants, delivering technical services for on-premises and an evolving suite of SaaS security products; supported pre-sales efforts by collaborating with Sales teams to define scopes, statements of work, and deployment requirements for security solutions.
  • Partnered with global clients across diverse industries (e.g., government, retail, telecom, healthcare, hospitality, tourism, education, military, real estate, media, and energy), aligning security products and processes with organizational programs.

GROUP HEALTH COOPERATIVE, Seattle, WA             2012–2013

Sr. Security Specialist, Information Security & Regulatory Compliance 

  • Developed and implemented processes and standards to identify, assess, and mitigate risks across technology architectures, ensuring robust security controls for sensitive healthcare data.
  • Maintained compliance with regulatory requirements and information security best practices, aligning critical systems with organizational and industry standards.
ADDITIONAL ROLES
  • T-MOBILE, Bellevue, WA | Senior Security Consultant, Vulnerability Management & Advisory Services | 2011–2012
  • STARBUCKS COFFEE COMPANY, Seattle, WA | Senior Security Consultant, PCI Remediation | 2011–2012
  • ACCUVANT, Denver, CO | Security Consultant, Penetration Testing | 2007-2009
  • HOLLAND AMERICA LINE, Seattle, WA | Information Security Analyst | 2006-2007
  • NETIFICE, Seattle, WA | Managed Services Network Engineer | 2005-2006

EDUCATION & CERTIFICATIONS

  • Certified Information Systems Security Professional (CISSP), Current
  • Bachelor of Applied Arts and Sciences (Network Programming & Organizational Leadership)  | University of the Incarnate Word, San Antonio, TX

INDUSTRY IMPACT & SPEAKING ENGAGEMENTS

  • ShmooCon: You and Me (But Mostly Me), Building a Product Security Incident Response Program | 2023
  • THOTCON/DerbyCon: Overcoming Imposter Syndrome (Even If You’re Totally Faking It) | 2016
  • DerbyCon: Putting the “Management” into “Vulnerability Management” | 2015
  • ToorCon Seattle: Not Another Boring VoIP Talk: Weaknesses in H.323 Carrier Implementations | 2008

Additional Speaking Engagements: SC Media 20/20 Webcast, InterFace Phoenix, ISACA Seattle and Portland