Mark 𪢠Szewczul
Director - Enterprise Product Security @ JPMorganChase
About
Over two decades of leadership experience (5 years in management) across diverse domains, including: ⢠Pentesting: Probed systems, uncovering vulnerabilities and fortifying defenses. ⢠Open-Source Software: Commitment to open-source principles drives innovation and collaboration. ⢠Secure-SDLC: Ensuring security at every stage of software development. ⢠SBOM Provenance: Tracking software components for transparency and risk mitigation. ⢠Infrastructure, Cloud, and API Security: Safeguarding digital landscapes against threats. ⢠Customer Security & Privacy: Prioritize aligning internal strategies with customer needs. ⢠Risk Management: Navigating the ever-evolving threat landscape. A multi-faceted approach: ⢠Innovation-Driven: Seek novel solutions that enhance revenue while optimizing costs. ⢠Results-Oriented: My track record speaks of achievements rooted in diligence and determination. ⢠Team Building: Foster collaborative environments where excellence thrives. ⢠Quick Learner: Adapting swiftly to emerging technologies and industry shifts. ⢠CISM Aspirant: Currently preparing for the Certified Information Security Manager (CISM) exam.
United States
Dallas-Fort Worth Metroplex
Computer Software
Leadership, Security Champions, Web Services API, CISO Office, Red Teaming, Penetration Testing, Team Building, IT Risk Management, Quantum Computing, Artificial Intelligence (AI), Technical Leadership, Team Management, People Management, ciso, Threat & Vulnerability Management, Cyber Threat Intelligence (CTI), Software Development Life Cycle (SDLC), Software Development, Application Security, Mobile Applications
Experience

vCISO Services, AI & Quantum Application Research
Virtually There
⢠12th NTX ISSA Cybersecurity Conference: âThreat Detection in Boundaryless Environmentsâ panel 9/6/2024.
⢠CISO XC Conference: âStaying Compliant in Cloud Security with AIâ panel 4/25/2024.
⢠CISO XC Conference: âModernizing InfoSec: Staying in compliance with cloud & data securityâ panel 11/21/2023.
⢠Hexcon23: âSecuring the Future: The Intersection of Security and AIâ panel 11/20/2023.
⢠11th NTX ISSA Cybersecurity Conference: âPractical Tips for Career Advancementâ panel 11/15/2023.
⢠Mastering 5G Network Design, Implementation, and Operations

AppSec Principal Lead
San Francisco, California, United States
⢠Developed and led the application security strategy and program across the organization. ⢠Worked closely with development teams to integrate security practices into the SDLC, including threat modeling, secure coding practices, security testing, validation and vulnerability management. ⢠Led security assessments, code reviews, and penetration testing efforts to identify and mitigate security vulnerabilities in applications. ⢠Developed and maintained security policies, standards, and guidelines related to application security. ⢠Drove the selection and implementation of application security tools and technologies. ⢠Directed the implementation and maintenance of security controls to safeguard sensitive information and company assets. ⢠Communicated security risks and strategies to stakeholders, including executive leadership, in a clear and effective manner.

Security Center of Excellence Lead
⢠Leveraged MITRE frameworks and Cyber Threat Intelligence (CTI) to compile Attack/Adversary Playbook for Red/Blue Team operations for Product Security & Incident Response Teams (PSIRT). ⢠Ensured that Nokiaâs portfolio is compliant with customer and regulatory security requirements. ⢠Established the wide governance on product security for Nokia systems, with one focus on API security. ⢠Serviced security requirements and security regulations for Telecom, Enterprise, and Government markets. ⢠Evolved the vulnerability management platform âVAMSâ for the Nokia product portfolio which allows the Nokia product lines to identify vulnerabilities in the product and ensures fast fixes/disclosure to customers. ⢠Identified and evangelized best practices for product security both externally and internally to Nokia and ensured that they are adopted as appropriate. ⢠Developed the ASTaR (Advanced Security Testing and Research) End-to-End lab in Dallas for security testing with a focus on 5G solutions to prioritize test scenarios and execution in cooperation with the Business Groups, with results delivery.

Certification Committee Consultant: IOT, AI, Security, Privacy, Safety
As SME on Scheme Committee, was key contributor to the industry's first, vendor agnostic, IoT Practitioner Certification for professionals, IoT Security Practitioner Certification, as well as the Artificial Intelligence Practitioner Certification, all released. https://certnexus.com/certification/

Principal Application Security Architect
Dallas-Fort Worth Metroplex
⢠Mentored and Directed Security Analysts, Engineers and Architects. ⢠Led the Shift-Left strategy with Development and DevOps teams while composing enhanced SDLC Standard. ⢠Worked with Development and Operations on enhancing existing security posture of APIs. ⢠Designed security solutions that enforce security consistently across internally developed, commercial-off-the-shelf (COTS) and cloud-based applications and platforms (AWS, Azure) leveraging IAM, KMS, VPC. ⢠Performed security architecture reviews for secure, private, and compliant production datacenters (PCI, FedRAMP) leveraging Third-Party Risk Management tools (SCA, SAST, DAST, BitSight). ⢠Performed various Risk Assessments, Threat Modelling in order to advise for proper tradeoffs with business. ⢠Led design reviews with Development and Operations teams. ⢠Developed procedures to automate CD-CD pipeline security during code builds, testing and deployments. ⢠Collaborated with product and platform teams to maximize DevSecOps automation goals. ⢠Worked directly with Security Operations Center (SOC) and Technical Vulnerability Management (TVM). ⢠Member of Change Board and Vendor Risk Management for various ISMS procedures towards ISO 27001/27002, NIST CSF. ⢠Representative as Infosec Privacy Expert for Legal Department intake towards GRC.

Application Security Architect
Dallas-Fort Worth Metroplex
⢠Used Application Security tools within LLVM compiler toolchain to obfuscate application code/bitcode within the Secure SDLC. ⢠Demonstrated advanced understanding modern security concepts: malware, cryptography, disassembly, reverse engineering and exploitation methodologies. ⢠Utilized VMs, Containers, Linux, Python, JavaScript, Java, JSON, XML, Network stacks to demonstrate various POCs, including CI-CD pipelines, eg. Jenkins. ⢠Leveraged pentest tools such as Frida, JADX, bytecode-viewer, IDA Pro, Hopper. ⢠Provided consistent, proactive, technical leadership and expertise to ensure the success of the implementation and integration. ⢠Trained customerâs software architects, developers and security engineers in Arxanâs technology and security best practices.

Principal Vehicle Cybersecurity Architect
Dallas/Fort Worth Area
⢠Recommended key decision points for technology direction and contributed to comprehensive technical roadmaps for the vehicle ecosystem with the right balance of tradeoffs for security/privacy and customer experience. ⢠Converted business requirements into working solutions by creating Secure Application Development and Privacy Policies (PCI, GDPR, CCPA), DevSecOps, Threat Modeling ECUs, Root of Trust/Secure root Purple Team, CI-CD pipelines for any secure vehicle endpoint to backend server workflow for Toyota TMNA and other Toyota Entities (AWS, Azure, Embedded and Mobile focus). ⢠Made recommendations on best-of-breed vendor solutions and tools for mobile, server, embedded and safety using common frameworks (NIST, OWASP, CSA, IEC 61508, ISO 26262, SOTA, PKI, IAM). ⢠Evaluated technology with trials and POCs for mobile/server workflow. ⢠Worked with development teams on implementation with agile improvements. ⢠Represented Toyota Vehicle Security at SAE J3061 Cybersecurity for Cyber-Physical Vehicle Systems. ⢠Represented Toyota Vehicle Security at SAE J3138 for Diagnostic Link Connector Security.
Education

Information Science & Systems
Thesis option, Information Science and Systems concentration. Conference paper: ⢠Conference on Information Sciences and Systems: "Effect of Censoring In Detector Robustness and Performance in Nominally Laplace Noise," The Johns Hopkins University. Term papers/projects: ⢠Modulation Theory: âThe Performance of the Viterbi Algorithm for Convolutional Decoding: Hard vs. Soft Decision and Window Length Effectsâ ⢠Estimation and Detection Theory: âRobust Signal Detectionâ ⢠Data Compression: âThe FBI Fingerprint Image Compression Standardâ
Mark 𪢠Szewczul's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact dataâwithout paying for each one.
Great conversations start with the right contact.
Itâs time to find yours.



