Download the full PDF or connect on LinkedIn.
Professional Summary
Senior Cybersecurity Analyst with 3+ years securing enterprise applications and APIs at scale.
Specialises in web application and API penetration testing, threat modeling, and AI-driven security
automation. Demonstrated ability to own complex security programs end-to-end — from large-scale
WAF migrations to company-wide vulnerability initiatives — while translating technical risk into
actionable guidance for engineering and leadership.
Core Competencies
Web & API Penetration TestingThreat ModelingSecure Code ReviewSAST / DAST / SCAWAF / WAAP (Akamai, Cloudflare)CI/CD Security IntegrationAI/ML SecuritySnykDevSecOpsVulnerability ManagementPython · JavaScript · Java
Professional Experience
- Led Akamai to Cloudflare WAF migration covering 700+ applications, delivering $1.4M in cost savings within a three-month timespan.
- Engineered an AI-driven security automation tool that reduced report documentation time by 50%, enabling faster risk remediation across the enterprise.
- Designed and maintained SAST, DAST, and SCA pipelines integrated into CI/CD workflows, expanding threat detection coverage across engineering teams.
- Applied ML-based risk prioritisation to threat modeling workflows, improving remediation efficiency and guiding engineering partners toward higher-impact fixes.
- Provided security architecture guidance to development teams, hardening enterprise application configurations and influencing secure design decisions.
- Conducted manual and automated secure code review and penetration testing across web applications and APIs, identifying critical vulnerabilities with actionable remediation guidance.
- Led company-wide hardcoded secret detection initiative, independently identifying and remediating widespread credential exposure risk at scale.
- Integrated Snyk SAST/SCA into CI/CD pipelines, enabling development teams to identify and resolve vulnerabilities earlier in the SDLC.
- Delivered developer security training programs, raising secure coding adoption across multiple engineering organisations.
Projects
Building a full security operations stack from scratch — Security Onion, Wazuh, Sysmon,
Atomic Red Team, TheHive, MISP, and Velociraptor — to develop hands-on SOC analyst and
threat hunting skills. Each component is documented as a blog post at reganchamberlain.com/soc-lab.
Certifications
Certified AI/ML Pentester (C-AI/MLPEN) The SecOps Group · 2025
Generative AI Leader (GAIL) Google · 2025
Education
B.S. Information Technology University of North Florida · 2023