About Dave

Startup Founder

As the owner and lead developer of multiple startups, my talents include managing business affairs, marketing, and creating both SaaS and eCommerce services. These services include security products, commercial sales platforms, and a charitable, employment based advertising platform.

Security Researcher

As a security researcher, my work has progressed from incident response, to identifying indicators related to criminal campaigns, to researching state-sponsored APTs. I've combined this research with extensive Python & DevOps experience to produce deliverables essential for security intelligence work.

Software Engineer

My experience brings over 21 years of software development, and 15 years of security focused engineering to enterprises. My portfolio includes the creation of security products, Python based SaaS and commercial sales platforms, REST APIs, web services, backend infrastructure development, endpoint products, and more.

International Consultant

Advising colleagues in multiple countries across the globe, my 21 years of experience has helped mentor, support, and grow world class talent within information security, software development, and business. This support has helped inspire lives, improve profits, and create a solid foundation to prosper.

Resume

21 Years of Software Development
15 Years of Information Security

Experience

2022 - Present
Imply Data

Information Security Analyst

This role is an Information Security Analyst with Imply Data.

2019 - 2022
Pfizer

Senior Security Automation Engineer

This role was a Senior Security Automation Developer with Pfizer's Global Information Security Team.

Responsibilities Included:

  • Engineering solutions to ensure compliance with data loss prevention policies

  • Compliance driven collection of mobile application data sent within the APAC region; this project required Python bindings to C libraries, Splunk, Docker, Zookeeper, and Elastic

  • Administering a Security Orchestration, Automation, and Response (SOAR) platform

  • Providing automation support to incident response, threat intelligence, and insider threat teams

  • Conducting code reviews

  • Modernizing legacy infrastructure & engineering practices

  • Assisting management and mentoring team members

2017 - 2019
Kayod

Owner & Lead Developer

As the owner and lead developer, these roles included managing business affairs, marketing, and creating:

  • A Yara based endpoint security product that alerted clients about files containing sensitive data & measured the length of exposure over time

  • A GPS, WiFi & Cellular based mapping service

  • A charitable, employment based advertising platform tailored to the Republic of the Philippines

2012 - 2017
Arbor Networks

Security Research Analyst

This role was a Security Research Analyst on Arbor's Security Engineering & Response Team (ASERT).

Responsibilities included:

  • Reverse engineering malware, malware classification

  • Contributing to the company's malware analysis infrastructure development

  • Malware sinkhole development

  • Product feed contributions

  • Researching DDoS related threats & developing mitigations

  • Producing research & intelligence products for customers

  • Briefing media & responding to law enforcement inquiries

  • Point-of-contact for an ISAC

  • Understanding threat-actor TTPs & providing attribution to campaigns

  • Contributing to working groups & the security community

  • Researching new malware families, criminal, and state-sponsored campaigns

  • Presenting at private conferences

2008-2012
Southern Illinois University

Incident Responder

This role was working as an Incident Responder in the Information Security Department at Southern Illinois University Carbondale.

Responsibilities Included:

  • Identifying, containing, and monitoring the remediation of malware infections

  • Working with departments to implement best security practices

  • Developing a DNS-based sensor network to identify malware traffic

  • Creating infrastructure to detect malware traffic signatures from third-party feeds

  • Developing a passive DNS database

  • Forensic analysis of compromised devices

  • Reverse engineering malware

  • Identity management & compliance audits

  • Responding to law enforcement inquiries

  • Contributing to the TDL working group

  • Developing an endpoint security product

2006-2007
Southern Illinois University

Research Contract

This position involved contributing to the development of a communication paradigm for unmanned aerial vehicles under a research contract.

2006-2007
Southern Illinois University

Palm Pilot Application Development

This work involved contributing to the development of a Palm Pilot application used by clinical researchers at Southern Illinois University. The application enabled researchers to monitor and record behavioral interactions between members of at-risk communities. This software was used to support a long-standing study at the university.

2004-2005
Terry's Computer Shack

Employee

This role consisted of repairing and assmbling computers, removing malware infections, selling cellular phones, assisting customers, and installing satellite dishes in the Mendota, Illinois & surrounding area.

Education

2012
Southern Illinois University at Carbondale

B.S. Speech Communication

Specializations in Persuasive & Interpersonal Communication

2011
Southern Illinois University at Carbondale

B.A. Political Science

Minor in Speech Communication

Portfolio

My Works
Kayod

Kayod.ph

SaaS

Blog

My Thoughts

Contact

Get in Touch

Orlando, FL

dave@dloftus.com

Consulting Available