Cloud & application security engineer · Philadelphia
Joe Dickinson
I secure software where it is built and where it runs: code, pipelines, containers and the cloud underneath them.
From defensive tooling for the NSA and U.S. Navy ships to container and application security for a Fortune 500 insurer. I write the code, run the scanners, break the apps, and show developers exactly what to fix.
Greater Philadelphia · Remote · Open to conversations
11+
years in security engineering
100+
security professionals briefed in the CISO organization
Career arc · 2006 to today
From writing the software to securing it
Each bar is a role, colored by the kind of work. Select a bar to see what I did there.
Select a bar above, or step through
May 2025 – presentAmerican Family Insurance · Remote
Lead Cloud Platform Engineer
Led enterprise testing and rollout of runtime anomaly detection for containers with Palo Alto Prisma Cloud and Cortex Defender agents.
Rebuilt the non-functional container security integration in GitLab CI/CD for AWS (EKS, ECS) and GKE. Hundreds of containerized applications now scan through it.
Built Terraform automation for golden-image deployments in Azure and led Infrastructure-as-Code policy controls in GitLab pipelines.
Integrated Prisma Cloud with AWS, XSOAR and ServiceNow for agentless scanning, and wrote the enterprise container security standards.
Aug 2020 – May 2025American Family Insurance · Remote
Lead Application Security Engineer
Subject-matter expert for Snyk SCA, Snyk Code SAST and Prisma Cloud Compute. Wrote the GitLab includes (Bash, Python) that scan thousands of applications across five operating companies.
Ran internal penetration tests and Burp DAST triage so developers only received true-positive findings.
Led STRIDE threat modeling, manual code review, vulnerability remediation management and company-wide incident response for critical vulnerabilities.
Oct 2018 – Apr 2020Nuix · Remote
Application Security Engineer
Introduced the secure SDLC: Checkmarx, Coverity and AppScan SAST plus Nessus scanning wired into CI/CD.
Penetration tested seven Nuix products, desktop and web, and briefed C-suite executives on business risk.
Wrote the application security documentation for ISO 27001 certification and trained engineers on OWASP Top 10, OWASP API Top 10 and SANS Top 25.
Sep 2016 – Sep 2018Naval Surface Warfare Center · Philadelphia
Cyber Security Software Engineer
Led Python development of a shipboard situational-awareness tool that monitors boundary traffic for anomalies.
Wrote tshark/Python tooling to hunt through ship packet captures and analyzed pcap data in breach scenarios.
Hardened ship software with SonarQube and Nessus, reviewed Java code by hand, built sample exploits, evaluated NIDS products and mentored junior engineers. Secret clearance.
Feb 2015 – Sep 2016National Security Agency · Fort Meade, MD
Software Engineer
Lead for software security on the team: guided developers and stakeholders and delivered remediations for identified vulnerabilities.
Built Python/Django applications in Docker, hardened Ruby on Rails software and tuned MySQL, Oracle, PostgreSQL and MongoDB. TS/SCI clearance.
Jul 2014 – Jan 2015Drexel University, Digital On-Ramps · Philadelphia
Software Engineer
Federally funded literacy project: built the LAMP/Drupal career-pathways app, wrote an open-source Python tool to manage Drupal updates and backups, and ran the Ubuntu web server and TLS.
Nov 2013 – May 2014VulnAware · Wayne, PA
Founder
Built a SaaS web-application vulnerability scanner (Python, Django, AWS EC2, Nginx) focused on fewer false positives, and piloted it with clients.
Jul 2012 – Nov 2013QVC · West Chester, PA
Application Developer
Java and DB2 development on QVC.com. Found and fixed numerous SQL injection vulnerabilities and business-logic defects affecting thousands of customers.
2006 – 2011While at Drexel
Co-ops and student roles
Independence Blue Cross (data warehouse developer), PJM Interconnection (C# ASP.NET developer), NAVSEA (student engineer, Secret clearance), Drexel IRT help desk, VisionLineMedia web design.
Secure SDLC coverage
Hands-on at every stage of delivery
The tools and techniques I have used myself, at each stage from design to runtime.
Languages
PythonBashJavaC++PHPSQL
Containers
KubernetesOpenShiftDockerPodman
Cloud
AWSAzureGCP / GKE
Depth by domain
Years of hands-on practice
Counted from role dates, not self-rated. Overlapping roles count once.
Selected work
Problems I was brought in to solve
0 → 100s
containerized apps scanned on every build
Container security pipeline, rebuilt
American Family Insurance · 2025
ProblemThe GitLab container scanning integration was broken. Images shipped unscanned.
FixRebuilt it for EKS, ECS and GKE. Added Prisma Cloud agentless scanning for AWS.
ResultScanning across GitLab Registry and ECR, plus enterprise container standards.
5
operating companies on one scanning standard
One pipeline include, thousands of apps
American Family Insurance · 2020–2025
ProblemScanning was inconsistent across Perl, Java, Python, JavaScript and C#.
FixWrote reusable GitLab includes for Snyk SCA, Snyk Code and Prisma Cloud.
ResultUniform SAST, SCA and Prisma Cloud container scanning, with findings triaged to true positives.
7
products penetration tested
An AppSec program for a software vendor
Nuix · 2018–2020
ProblemNo secure SDLC, and ISO 27001 certification on the roadmap.
FixSAST and DAST in CI/CD, STRIDE threat models, OWASP training.
ResultAppSec documentation for ISO 27001; risk briefed to the C-suite.
Ship-ready
defensive tooling, lab to installation
Situational awareness for Navy ships
NAVSEA · 2016–2018
ProblemShip networks needed to spot anomalous traffic and foreign actors.
FixLed Python development of a boundary-monitoring tool; wrote pcap hunting scripts.
ResultBuilt and tested in the lab, then installed on shipboard systems.
Recommendations
Recommendations
Joseph is extremely innovative and well ahead of his time. He is hard working and a fantastic motivator.
Dianna L. Mathews via LinkedIn
Joe is an honest, hardworking and punctual guy…
Altaf H. via LinkedIn
Need someone who can secure the pipeline and still ship?
I'm open to conversations about cloud security, application security and DevSecOps roles, and to speaking about container security in practice.