Charlie Williams

Application
Product
Cloud
Mobile
DevOps
AI
Data
Security

Summary

Application Security Engineer with over 9 years of experience architecting, deploying, and scaling robust security programs in both enterprise and startup environments. Passionate about product security and user privacy, I empower teams to weave security into every phase of the development lifecycle—leveraging SAST, SCA, DevSecOps, and cloud/API protections—without slowing velocity. By driving data-driven insights and metrics, I focus on the highest-impact interventions to deliver resilient, secure software that supports business goals.

Secure Code & Dependencies SAST SCA Supply Chain Security
Cloud & API Security AWS WAF/API Security Authentication
DevSecOps & Automation GitHub Actions Dependabot Terraform
Secure Development Threat Modeling OWASP Top 10 Secure Architecture

Work Experience

Upside

Staff Application Security Engineer

Application Security Lead
- Present

Leading the Application Security program within Upside's Product Security team by embedding security into the product development lifecycle to enhance code quality and sustain rapid delivery. Design and deliver developer-centric secure-coding tools and best practices. Harness data engineering to produce actionable security metrics and champion automated controls (SAST, SCA, IaC scanning) across engineering teams. Partner with product and engineering to streamline security workflows, strengthen overall posture, accelerate delivery, and enable data-driven business decisions.

Booz Allen Hamilton

Lead Engineer

Application Security
-

Helped establish the U.S. Department of Veterans Affairs' first Application Security program, safeguarding patient data and enhancing security for thousands of applications. Conducted SAST scans using Fortify and collaborated with teams to reinforce secure coding practices across hybrid environments.