Carlos R. Gomez

Security Engineering Manager, Insider Threat Detection & Response

Background

Highly motivated Security Engineering Manager with a strong background within Insider Threat Detection & Incident Response. Over 8 years working with a mixed audience of technical skill sets providing incident management across multidisciplinary enterprises.

Leveraged past experiences in threat intelligence, to develop an Insider Threat Mitigation Program (ITMP) within Amazon (Ring). Ultimately the success of this program's risk mitigation & detection capabilities lead to the expansion across Amazon Devices Subsidiaries & Acquisitions (Amazon Key, Blink, Eero, Ring, Zoox).

Expertise

Incident Management
88%
Business Strategy
80%
Operational Planning
77%
Resource Budgeting
72%
Talent Management
82%

Work Experience

2023 - Present

Manager III Security Engineering | Insider Threat Detection & Response

Amazon, Devices - Subsidiaries & Acquisitions (Amazon Key, Blink, Eero, Ring, Zoox)
2021 - 2023

Manager II Security Engineering | Insider Threat Detection & Response

Amazon, Devices (Ring)
2018 - 2020

Security Engineer II | Incident Response

Ring
2018 - 2018

Security Analyst | CDN Web Application Firewall

Verizon Digital Media Services
2016 - 2018

Engineering Support Specialist | ITRP

Google Inc.
2017-2017

DevOps (Rotation) | Google Cloud Partner Eng.

Google Inc.
2016-2016

Operations Specialist | Production Technology

DreamWorks Animation
2015-2016

Information Systems Administrator | Production Technology

Blur Studio

Education

AS Behavioral & Social Sciences

Los Angeles Southwest College

BS Information Systems Security

Azusa Pacific University
Sabbatical

MS Homeland Security | Information Security & Forensics

Penn State University (World Campus)

Projects

Reliability Engineering

Ring | Unified Severity Ratings (Implementing SLO/SLI Adoption)

Scope: Proposed a unified rubric for production service leads to adopt service level objectives (SLOs). Notion: “if reliability is a feature, when do you prioritize it versus other features?”.

Contributions:

  • Defined SLO principle around Customer Reliability Engineering; device reliability is the most important feature. Set prioritization abstract, incidents should not be handled on a first-come, first-served basis as a result of resource limitations. Instead, should be prioritized based on relevant factors: Functional Impact, Information Impact, Recoverability.
  • Turned arguments, into data-driven decisions with Executive Support, driving operation response & setting long-term prioritization.
  • Quantified missed reliability targets; introduces axes of improvement: E ~ (time-to-detect + time-to-response) x impact% / time-to-fix
  • Developed Case Prioritization Engine (RCPE), weighted response & Ring Severity Selection Levels (RSSLs).

Security Service Team (RSST)

Ring | Established 1st Security Service Team

Scope: Built RSST leveraging existing agents interested in a career path into Security Operations. Agents are responsible for their current core duty role as Ring Technical Customer Support, but also tasked with monitoring, and triaging inbound customer security related items.

Contributions:

  • Outlined project stakeholders, gaining insight on requirements from both operational and compliance perspective.
  • Measured metrics, by developing inbound CRM model; breaking down customer requests by introducing tag allowing stakeholders to gain optics on (Items Escalated from CS Call Centers to SecOps vs. Items Escalated to SecOps that convert to IRs).
  • Leveraged metrics to gain stakeholder approvals from CTO, SVP, Operations Management, SecOps Leads, showcasing potential to reduce Security Engineering burnout.
  • Defined RSST role, which was adopted by CS Ops Management for the purposes of hiring for the role internally.
  • Co-Authored internal Corporate Engineering Knowledge Base Articles (CEKBs) aka playbooks, that are leveraged by RSST when conducting core duty triage/escalations.

Google IT Support Professional Certificate (Mentor/Forum Moderator)

Coursera | Provide universal access to the world’s best education

Scope: Google & Coursera established a certificate program to train Americans, including those without a college degree, for entry-level IT jobs. IT initiative is one part of a larger $1 billion effort by Google, focused on skills, and education, to help workers find their footing in a U.S economy disrupted by technology.

Contributions:

  • Mentor course participants through a dynamic mix of hands-on labs, widgets, and code blocks.
  • Increase participation, motivating learners, and leading productive discussions.
  • Moderate forums (e.g. remove inappropriate posts or answers to assessments, etc.)
  • Address, and mitigate course context errors, along with providing Coursera users with online troubleshooting support.

SkyEye Access Intelligence

Google | Access Control Infrastructure (ACI)

Scope: Establish and harden enforceable access control infrastructure. SkeEye is a data aggregation project developed to make information about Temps, Vendors, and Contractor (TVC) access controls and applications usage more readily available.

Contributions:

  • Reviewed SkyEye detailed designs documentations and protocols for handoff to Enterprise Infrastructure Protection (EIP) team. Ensuring project scope-maintained alignment with EIPs mission to keep Google User Data safe by protecting Googlers and the compute infrastructure they use to access it, maintaining a balance between security and usability
  • Optimized BigQuery tables in which materialized raw data was no longer over written but stored in a date-based hierarchy. This also improved data query load times.

Grow Cloud Adoption: Open Source Projects

Google | Google Cloud Platform

Scope: Contribute code, and documentation to various open source projects to support Google Cloud Platform.

Contributions: