Carlos R. Gomez
Security Engineering Manager, Insider Threat Detection & Response
Background
Highly motivated Security Engineering Manager with a strong background within Insider Threat Detection & Incident Response. Over 8 years working with a mixed audience of technical skill sets providing incident management across multidisciplinary enterprises.
Leveraged past experiences in threat intelligence, to develop an Insider Threat Mitigation Program (ITMP) within Amazon (Ring). Ultimately the success of this program's risk mitigation & detection capabilities lead to the expansion across Amazon Devices Subsidiaries & Acquisitions (Amazon Key, Blink, Eero, Ring, Zoox).
Expertise
Work Experience
Manager III Security Engineering | Insider Threat Detection & Response
Amazon, Devices - Subsidiaries & Acquisitions (Amazon Key, Blink, Eero, Ring, Zoox)
Manager II Security Engineering | Insider Threat Detection & Response
Amazon, Devices (Ring)
Security Engineer II | Incident Response
Ring
Security Analyst | CDN Web Application Firewall
Verizon Digital Media Services
Engineering Support Specialist | ITRP
Google Inc.
DevOps (Rotation) | Google Cloud Partner Eng.
Google Inc.
Operations Specialist | Production Technology
DreamWorks Animation
Information Systems Administrator | Production Technology
Blur Studio
Education
AS Behavioral & Social Sciences
Los Angeles Southwest College
BS Information Systems Security
Azusa Pacific University
MS Homeland Security | Information Security & Forensics
Penn State University (World Campus)
Projects
Reliability Engineering
Ring | Unified Severity Ratings (Implementing SLO/SLI Adoption)
Scope: Proposed a unified rubric for production service leads to adopt service level objectives (SLOs). Notion: “if reliability is a feature, when do you prioritize it versus other features?”.
Contributions:
- Defined SLO principle around Customer Reliability Engineering; device reliability is the most important feature. Set prioritization abstract, incidents should not be handled on a first-come, first-served basis as a result of resource limitations. Instead, should be prioritized based on relevant factors: Functional Impact, Information Impact, Recoverability.
- Turned arguments, into data-driven decisions with Executive Support, driving operation response & setting long-term prioritization.
- Quantified missed reliability targets; introduces axes of improvement: E ~ (time-to-detect + time-to-response) x impact% / time-to-fix
- Developed Case Prioritization Engine (RCPE), weighted response & Ring Severity Selection Levels (RSSLs).
Security Service Team (RSST)
Ring | Established 1st Security Service Team
Scope: Built RSST leveraging existing agents interested in a career path into Security Operations. Agents are responsible for their current core duty role as Ring Technical Customer Support, but also tasked with monitoring, and triaging inbound customer security related items.
Contributions:
- Outlined project stakeholders, gaining insight on requirements from both operational and compliance perspective.
- Measured metrics, by developing inbound CRM model; breaking down
customer requests by introducing
tag allowing stakeholders to gain optics on (Items Escalated from CS Call Centers to SecOps vs. Items Escalated to SecOps that convert to IRs). - Leveraged metrics to gain stakeholder approvals from CTO, SVP, Operations Management, SecOps Leads, showcasing potential to reduce Security Engineering burnout.
- Defined RSST role, which was adopted by CS Ops Management for the purposes of hiring for the role internally.
- Co-Authored internal Corporate Engineering Knowledge Base Articles (CEKBs) aka playbooks, that are leveraged by RSST when conducting core duty triage/escalations.
Google IT Support Professional Certificate (Mentor/Forum Moderator)
Coursera | Provide universal access to the world’s best education
Coursera | Provide universal access to the world’s best education
Scope: Google & Coursera established a certificate program to train Americans, including those without a college degree, for entry-level IT jobs. IT initiative is one part of a larger $1 billion effort by Google, focused on skills, and education, to help workers find their footing in a U.S economy disrupted by technology.
Contributions:
- Mentor course participants through a dynamic mix of hands-on labs, widgets, and code blocks.
- Increase participation, motivating learners, and leading productive discussions.
- Moderate forums (e.g. remove inappropriate posts or answers to assessments, etc.)
- Address, and mitigate course context errors, along with providing Coursera users with online troubleshooting support.
SkyEye Access Intelligence
Google | Access Control Infrastructure (ACI)
Scope: Establish and harden enforceable access control infrastructure. SkeEye is a data aggregation project developed to make information about Temps, Vendors, and Contractor (TVC) access controls and applications usage more readily available.
Contributions:
- Reviewed SkyEye detailed designs documentations and protocols for handoff to Enterprise Infrastructure Protection (EIP) team. Ensuring project scope-maintained alignment with EIPs mission to keep Google User Data safe by protecting Googlers and the compute infrastructure they use to access it, maintaining a balance between security and usability
- Optimized BigQuery tables in which materialized raw data was no longer over written but stored in a date-based hierarchy. This also improved data query load times.
Grow Cloud Adoption: Open Source Projects
Google | Google Cloud Platform
Scope: Contribute code, and documentation to various open source projects to support Google Cloud Platform.
Contributions:
- Developed and participated in open source project integrating Ansible with Google Cloud Platform to create and bootstrap instances, install Apache, and setup Compute Engine load-balancer
- Patched repository to provide updated details necessary to replicate recorded demo ( Ansible and Compute Engine: A 10 minute Video Tutorial).
- Revision of GitHub (README.md) “Google Cloud Platform Project”