Matthew McStravick

Matthew McStravick

About

Detail

Head of Security Engineering
United States

Timeline


work
Job
school
Education

Résumé


Jobs verified_user 0% verified
  • Riveron
    Head of Security Engineering
    Riveron
    Jan 2026 - Current (8 months)
    • Orchestrate the strategic direction for cloud security engineering across AWS, GCP, and Azure client environments by defining scalable security architectures, engineering standards, and technical controls that strengthened security posture. • Act as a virtual Chief Information Security Officer (vCISO) for a portfolio of small business and mid-market clients while advising executive leadership on enterprise risk strategy, security roadmaps, and program maturity. • Direct cloud security engineering initiatives spanning identity and access management, infrastructure hardening, vulnerability management, and secure deployment practices. • Embedded security-by-design principles into cloud-native environments by partnering with platform and DevO
  • Quizlet
    Staff Cloud Security Engineer - Tech Lead
    Quizlet
    Sep 2024 - Jan 2026 (1 year 5 months)
    • Successfully strengthened production Vertex AI infrastructure through the implementation of network isolation, least-privilege IAM, model artifact protection, and centralized logging and monitoring. • Engineered comprehensive AI security guardrails to mitigate risks associated with data leakage, model poisoning, and prompt injection while collaborating closely with machine learning and product engineering teams to integrate security throughout the model development lifecycle without impacting release velocity. • Implemented role-based access controls across production Google Kubernetes Engine (GKE) clusters by enforcing least-privilege access, workload identity segregation, namespace isolation, and Infrastructure-as-Code deployment practi
  • Qualcomm
    Staff Security Engineer - Insider Threat
    Qualcomm
    Feb 2023 - Aug 2024 (1 year 7 months)
    • Developed Qualcomm's enterprise AWS security baseline by implementing IAM policies, GuardDuty, Security Hub, AWS Config rules, and Service Control Policies (SCPs) aligned with FedRAMP High, CIS Benchmarks, NIST 800-171 Rev. 2, and CMMC while reducing manual audit evidence collection while accelerating government project approvals. • Performed STRIDE-based threat modeling during the design phase of new systems and architectures to identify security weaknesses before deployment while preventing costly re-architecture efforts and improving overall security resilience. • Engineered automation, correlation rules, dashboards, and detection content to identify insider-risk indicators, including data exfiltration, anomalous access patterns, and p
  • Lockheed Martin
    Cyber Systems Security Engineer II
    Lockheed Martin
    Apr 2022 - Feb 2023 (11 months)
    • Modernized enterprise CI/CD security scanning processes by integrating Aqua, Fortify, SonarQ, and secret-scanning technologies into vulnerability scanning and remediation workflows with a focus on reducing critical vulnerabilities within production releases while increasing developer confidence in automated security gates. • Advanced compliance initiatives aligned with NIST 800-171 and FedRamp requirements to enable the secure handling of sensitive defense information while maintaining eligibility for high-value government contracts. • Evaluated cyber risk across enterprise systems through comprehensive threat modeling, vulnerability analysis, and mitigation planning to prioritize high-impact security risks and reduce mean time to remedia
  • Lockheed Martin
    Cyber Systems Security Engineer I
    Lockheed Martin
    Jul 2021 - Apr 2022 (10 months)
    • Executed platform security assessments, code reviews, and architecture evaluations for applications supporting the Space Systems business unit while supplying critical security findings that informed go/no-go decisions for systems handling high-value mission data. • Conducted malware and beaconing investigations using Wireshark to identify, analyze, and contain malicious network traffic across the Lockheed Martin Intranet (LMI) while reducing the risk of data exfiltration and operational disruption. • Supported security engineering activities throughout the software and system development lifecycle while integrating security requirements into system architecture from design through sustainment to support mission assurance and regulatory c
  • American Airlines
    Security Engineer I - CIRE (Cyber Incident Response Engineering)
    American Airlines
    Mar 2021 - Jul 2021 (5 months)
    • Automated privileged Active Directory access reviews through Python scripting to identify excessive permissions and privilege drift with a focus on reducing insider threat exposure while supporting TSA and FAA cybersecurity compliance requirements. • Applied in-depth knowledge of adversary tactics, techniques, and procedures including Kerberoasting, credential theft, phishing, malware, and social engineering to strengthen endpoint detection strategies tailored to aviation IT and OT environments. • Optimized endpoint security configurations across flight operations workstations, kiosks, and server environments by improving system hardening measures while maintaining the availability of mission-critical, safety-regulated systems operating o
  • Exelon
    Project Manager I - IoT Security
    Exelon
    Apr 2019 - Mar 2021 (2 years)
    • Took the lead in configuring intrusion prevention and intrusion detection capabilities on Check Point firewalls across Exelon's WAN while improving network threat detection and protection for operational technology (OT) infrastructure supporting substations, power plants, and cell towers. • Facilitated the enforcement of information security policies, standards, and governance requirements across operational technology environments while helping bridge organizational security objectives with day-to-day technical implementation. • Evaluated large-scale firewall rule sets and operating system version data across OT environments to identify security gaps, configuration inconsistencies, and outdated systems to enable stakeholders to prioritiz
  • Penn Medicine University of Pennsylvania Health System
    Network Engineer I
    Penn Medicine University of Pennsylvania Health System
    May 2018 - Apr 2019 (1 year)
    • Accountable for maintaining Tier 2 and Tier 3 support for enterprise WAN and LAN infrastructure by diagnosing and resolving complex routing, switching, and connectivity issues across a healthcare data center environment to help ensure the continuous operation of critical hospital systems. • Administered IP addressing, subnetting, VLAN configurations, and gateway routing across Extreme Networks SLX 9640/9540 routers and ERS 5900 switches while maintaining the performance and reliability of core enterprise network infrastructure. • Improved network availability through infrastructure optimization initiatives focused on redundancy, segmentation, switching, and routing enhancements while increasing resilience for business-critical healthcare
  • Avantor
    Jr Network Administrator
    Avantor
    Jun 2015 - May 2018 (3 years)
    • Maintained enterprise IT operations by resolving network, system, connectivity, and user access issues across a regulated Good Manufacturing Practice (GMP) environment to help ensure the stability and reliability of day-to-day business operations. • Controlled user access through the administration of Active Directory accounts, security groups, shared network resources, ADP, Outlook, and other enterprise systems to ensure appropriate permissions were assigned in accordance with organizational requirements. • Installed new network services and infrastructure enhancements by translating departmental and business requirements into scalable technical solutions that supported evolving operational needs. • Validated network configurations and i
Education verified_user 0% verified
  • Western Governors University
    Bachelor of Science - BS, Cyber Security And Information Assurance
    Western Governors University
    Sep 2014 - May 2019 (4 years 9 months)
  • Upper Darby Senior High School
    High School Diploma, General Studies
    Upper Darby Senior High School
    Jan 2010 - Jan 2014 (4 years 1 month)
This is a community-created genome.