John Ellingsworth john@ellingsworth.org | https://johnellingsworth.com/resume ________________ PROFILE Product security leader with 15+ years building and scaling security programs across enterprise cloud environments. Co-author of OWASP SAMM v2.0 with demonstrated expertise embedding security into engineering culture, establishing Security Champions networks, and driving DevSecOps transformation. Proven track record delivering measurable security outcomes-32% vulnerability reduction, 95% security tool adoption-across 115+ applications and 36+ product teams while maintaining development velocity and business growth. ________________ CORE COMPETENCIES Security Program Leadership: Secure SDLC implementation * Security Champions program design * DevSecOps culture transformation * Framework-driven security maturity (OWASP SAMM, ASVS, NIST SSDF) Security Tooling & Automation: SAST/DAST/SCA/IaC scanning * CI/CD security integration * GitHub Advanced Security enterprise deployment * Vulnerability management orchestration * Cloud security posture management Cloud Security Architecture: Multi-cloud security (AWS, Azure, GCP) * Secure-by-design principles * Architecture & design reviews * Threat modeling * Enterprise security patterns Cross-Functional Leadership: Executive stakeholder management * Risk translation & communication * Engineering partnership & enablement * Compliance alignment (GDPR, HIPAA, PCI-DSS, SOC 2) ________________ PROFESSIONAL EXPERIENCE IDEXX Laboratories, Inc. Senior Manager, Product & Application Security | Aug. 2024 - Present Led product security strategy and execution protecting $1.5B revenue across 115+ applications, 36+ product teams, and multi-cloud infrastructure supporting global veterinary diagnostics operations. Security Program Strategy & Execution * Architected and deployed comprehensive security program based on OWASP SAMM framework, establishing measurable maturity progression across Design, Implementation, Verification, and Operations domains * Drove enterprise WAF initiative as top 2026 strategic priority, partnering with platform and infrastructure teams to scale secure-by-design principles * Achieved 32% vulnerability reduction through risk-based prioritization framework integrating EPSS scoring, CISA KEV, and business criticality ratings * Established security metrics and continuous improvement processes tracking critical vulnerability remediation within 15-day SLA with zero critical vulnerabilities over 30 days old Security Tooling & DevSecOps Automation * Led Application Security Stack Standardization achieving 95% GitHub Advanced Security adoption across enterprise development teams through phased rollout, training, and CI/CD integration * Implemented automated security analysis across SAST, DAST, SCA, and IaC scanning tools, operationalizing security throughout development pipelines * Deployed vulnerability management orchestration platform (Nucleus) unifying findings across Tenable, CrowdStrike, AquaSec, and GitHub Advanced Security for enterprise-wide visibility * Drove cloud security tool consolidation reducing redundancy and achieving $125-150K cost savings while improving security coverage Secure Development Lifecycle & Architecture * Established secure code review, threat modeling, and architecture review processes integrated into product development lifecycle across diverse product lines * Conducted design reviews identifying and addressing security risks early in development, preventing costly late-stage remediation * Built reusable security patterns and libraries for authentication, authorization, data protection, and secure API design adopted across engineering teams * Standardized security verification services offering 20+ assessment types from automated scanning to penetration testing and red team exercises Engineering Culture & Cross-Functional Partnership * Designed and scaled Security Champions Program embedding 40+ security advocates within delivery teams, creating force multiplier network that drives security ownership at the team level * Partnered with DevOps and platform teams to commoditize security solutions, enabling self-service security tooling and reducing friction for developers * Collaborated with Legal, Risk, GRC, and Compliance teams ensuring alignment with regulatory requirements (GDPR, CCPA, HIPAA, PCI-DSS, SOC 2) while enabling secure innovation * Translated technical security findings into business risk language for executive audiences, securing buy-in for strategic security investments ________________ IDEXX Laboratories, Inc. Senior Security Principal | Sep. 2018 - Aug. 2024 Built Product Security Assurance Program from inception, establishing secure SDLC framework and security governance model across enterprise product portfolio. * Program Foundation: Scaled security program across 36 product teams (250+ developers), establishing IDEXX's secure SDLC framework based on OWASP SAMM maturity model * Security Architecture: Architected secure solutions for complex multi-cloud environments (AWS, Azure, GCP) protecting sensitive customer data across veterinary diagnostic platforms * Governance & Compliance: Established security governance model bridging Legal, IT, product leadership, and engineering teams to integrate security into business processes and ensure regulatory compliance * Threat Modeling & Risk Assessment: Led threat modeling initiatives identifying architectural security risks and implementing mitigation strategies across product lines * Tooling Strategy: Evaluated and implemented security testing tools (SAST/DAST/IAST) integrated into CI/CD pipelines for automated vulnerability detection ________________ IDEXX Laboratories, Inc. Senior Manager, Customer Commercial Solutions | Jan. 2017 - Sep. 2018 Managed enterprise DevOps teams delivering secure customer-facing platforms including CIAM, eCommerce, analytics, and CRM systems. * Secure Cloud Operations: Led security implementation for AWS-based Customer Identity & Access Management (CIAM) platform serving global customer base * Platform Security: Directed secure integration of Salesforce and Marketing Cloud platforms ensuring data privacy, compliance, and secure API integrations * DevSecOps Implementation: Embedded security throughout SDLC from requirements through production operations, establishing security quality gates in continuous delivery pipelines * Team Leadership: Managed cross-functional DevOps teams balancing security requirements with business velocity and customer experience ________________ IDEXX Laboratories, Inc. Senior Software Development Manager | Jan. 2015 - Jan. 2017 * Led software engineering teams implementing application security practices, identity management solutions, and secure operations * Integrated security quality gates into agile/scrum methodologies and continuous delivery pipelines * Established secure coding standards and practices adopted across development organization ________________ IDEXX Laboratories, Inc. Software Development Manager | June 2010 - Jan. 2015 * Managed development teams delivering secure customer-facing web applications for global veterinary diagnostics customers * Oversaw security architecture and implementation for enterprise systems handling sensitive customer and diagnostic data ________________ OWASP SAMM Project & OWASP Maine Chapter Core Team Member, Co-Author, Chapter Lead | 2017 - Present * OWASP SAMM v2.0 Co-Author: Core contributor to industry-leading Software Assurance Maturity Model framework rewrite, authoring Security Requirements, Security Architecture, Implementation, and Verification functions and practices * Global Training & Speaking: Conduct training and speaking engagements internationally on secure SDLC, security maturity models, and DevSecOps best practices * Chapter Leadership: Lead OWASP Maine chapter fostering regional security community and promoting application security awareness * Industry Recognition: Established thought leadership in security maturity frameworks recognized across financial services, healthcare, technology, and government sectors ________________ EDUCATION & CERTIFICATIONS Massachusetts Institute of Technology | Executive Education Cybersecurity Playbook for Managers (2019) Drexel University | Master of Science (MSIS) Cybersecurity (2008) Temple University | Bachelor of Arts (B.A.) English/Philosophy (1999) ________________ KEY ACHIEVEMENTS * Co-authored OWASP SAMM v2.0, industry-standard framework for software security maturity assessment used globally across enterprises * Achieved 95% GitHub Advanced Security adoption across 115+ applications through strategic rollout, training, and CI/CD integration * Delivered 32% vulnerability reduction through risk-based prioritization framework and enhanced vulnerability management processes * Scaled Security Champions Program to 40+ advocates embedded within product teams, creating sustainable security culture * Built comprehensive security verification program offering 20+ assessment services from automated scanning to penetration testing * Led multi-cloud security architecture across AWS, Azure, and GCP supporting $1.5B revenue and protecting sensitive diagnostic data * Established security governance model bridging Legal, IT, Risk, and Engineering for enterprise-wide compliance and risk management ________________ TECHNICAL PROFICIENCIES Security Frameworks: OWASP SAMM, OWASP ASVS, NIST SSDF, CIS Controls, OWASP Top 10, MITRE ATT&CK Security Tools: GitHub Advanced Security, Snyk, Veracode, Checkmarx, SonarQube, Aqua Security, Tenable, CrowdStrike, Synack, Burp Suite, OWASP ZAP Cloud Platforms: AWS (Security Hub, GuardDuty, IAM), Azure (Security Center, Defender), GCP (Security Command Center) DevSecOps: CI/CD security integration (Jenkins, GitHub Actions, GitLab), Infrastructure-as-Code security (Terraform, CloudFormation), container security, Kubernetes security Development & Scripting: Python, PHP, Bash, YAML, JSON, secure coding practices Vulnerability Management: CVSS, EPSS, CISA KEV, vulnerability orchestration platforms, risk-based prioritization Compliance & Governance: GDPR, CCPA, HIPAA, PCI-DSS, SOC 2, SOX, security policy development, risk assessments