Security Engineering
Security Engineering
I spent two years as Security Engineer II at Tinder in West Hollywood. Before that, I managed bug bounty programs at Verizon Media, ran HIPAA compliance at Children's Hospital Los Angeles, and did vulnerability remediation across 5,000+ assets at UCLA Health. I've seen what happens when security is an afterthought — and when it's built in from day one.
Here's the truth most Los Angeles businesses don't want to hear: you're probably one bad day away from a breach, and you don't know where the hole is. The gap between "we have a privacy policy" and "we actually pass a security audit" is enormous. And most businesses don't find out until it's too late.
Forget the jargon. Here's what I check first when I audit a Los Angeles business:
Most businesses have no idea. Former employees still have access. Shared passwords. Admin rights handed out like candy. Zero Trust Architecture means verifying every access request, every time — not trusting someone because they're "inside the network." The fix is simple. Most businesses just haven't done it.
If you're not logging and monitoring, you can't detect a breach until it's already in the news. I deploy Splunk SIEM with custom detection rules so you see threats in real time, not three months later when a reporter calls.
At Tinder, I built SOAR playbooks that automated threat detection and incident response end-to-end. When a threat is detected, the system responds automatically — isolating the asset, blocking the IP, alerting the team. Increased SOC efficiency by 50%. A human reading an alert and deciding what to do takes three days. The playbook takes three seconds.
If you're a healthcare business in Los Angeles — a dental office, a clinic, a therapy practice — HIPAA compliance isn't optional. I've maintained 100% HIPAA audit compliance at Children's Hospital Los Angeles through precision SIEM tuning. The fines for non-compliance can destroy a practice. "We have a privacy policy" is not the same as "we pass an audit."
You can't fix what you don't know about. I use Rapid7 and Tenable to find every hole in your environment, then prioritize remediation by risk level. At UCLA Health, I executed vulnerability remediation across 5,000+ assets ensuring HIPAA compliance across critical healthcare infrastructure.
Los Angeles has one of the highest concentrations of healthcare businesses in the country. From small dental practices in Torrance to therapy offices in Santa Monica — most are not HIPAA compliant and don't know it. The gap between "we have a privacy policy" and "we actually pass a HIPAA audit" is enormous.
A system you can't audit isn't a system you can trust. That's the whole reason I do security the way I do — documented, verifiable, and built for the real world.
Don't wait for a breach to take security seriously. I offer a free 30-minute security assessment for Los Angeles businesses. I'll look at your environment, identify the biggest holes, and give you a written remediation plan. No scare tactics — just a straight answer about what's exposed and what to fix first.
Book a free 30-minute systems audit. I'll take real notes and hand you a written game plan — no pitch, no pressure.
Start the Discovery ↗