Technology, Information and Media
Active

Aleksandr K

Researcher | Advisor | Security Engineer | Inventor | vCISO

About Me

Most organizations view security as a series of patches; I view it as a programmable ecosystem. With a career forged at companies like Meta, Dropbox, and Palo Alto Networks, I offer a rare "full-stack" security consultancy. I don't just advise on risk—I engineer the automated systems that eliminate it. Whether acting as your vCISO to define your roadmap or as your Lead Security Engineer deploying eBPF-driven defenses, I ensure your infrastructure is as resilient as it is innovative. 🛠️ The Full-Spectrum Service Suite I provide comprehensive security consulting across five critical pillars: vCISO & Strategic Advisory: I translate complex technical debt into 3-year execution roadmaps. From driving Zero Trust initiatives to designing Secret Management strategies, I align security with business velocity. Product Security (The "Shift Left" Expert): I build the guardrails that allow developers to move fast. This includes full SAST/DAST integration, API security (REST/GraphQL), and redesigned authentication flows to crush OAuth abuse and account takeovers. Cloud & Infrastructure Security: I automate the "scary stuff." I specialize in SRE-focused IaC security(, Kubernetes network visibility, telemetry, and security, and building automated SOC services that save your team 20+ hours a week. Security Research & Invention: I bring years worth of experience ranging from hunting 0-day exploits, traditional bug bounty hunting, all the way to full on US Patent filing. Vulnerability Management: I don't just find bugs; I build the source-of-truth inventory for every dependency in your stack, ensuring whole classes of vulnerabilities are eradicated, not just reported.

Jurisdiction

Canada

Experience

Seniority LevelDirector
Years of Experience10-15 years
Current StatusActive
Principal Security Engineer / TLMMeta
2023 - Present

Zero Trust, Platform Security, Product Security, Security Partnerships, Offensive Security, Security Exploitation Development, Vulnerability Management, Security Leadership.

Staff Security Engineer / TLMThinkific
2022 - 2023

Product Security, Infrastructure Security, Security Partnerships, Compliance and Risk, Security Leadership, Offensive Security.

Senior Security Engineer / TLDropbox
2020 - 2022

Platform Security, Product Security, Network Security, Infrastructure Security, Zero Trust, Offensive Security, Vulnerability Management.

Lead DevSecOpsPalo Alto Networks
2019 - 2019

DevSecOps, Security Leadership, Offensive Security

Principal Security EngineerBerea College
2018 - 2020

DevSecOps, DevOps, Application Security, Network Security, Secure Architecture, Offensive Security.

CTOThe Porte
2019 - 2020

Security Leadership, DevSecOps, Product Development

Education

Degree of Computer Science & MathematicsBerea College
2017 - 2020

Certification

Total Certifications3

OSCP

Offensive Security (OffSec)

OSEE

Offensive Security (OffSec)

OSWE

Offensive Security (OffSec)

Skills

Core skills0
Languages2

Languages

English
English (British)