David Wolf · Portfolio Use Case
Building a scalable, evidence-driven product security function for a global enterprise software platform.
Partnered with Splunk to build and scale the product security program, strengthen secure development practices, and create the evidence, process, and organizational alignment needed to support a global software platform and enterprise customer expectations. Helped build Splunk's secure SDLC maturity by translating product-security goals into repeatable engineering practices: SAST/DAST workflows, app certification criteria, vulnerability triage, remediation prioritization, security scorecards, customer-trust evidence, and BSIMM/SAMM-style maturity framing across products and marketplace applications. Helped unblock enterprise customer trust by improving Splunk's product-security evidence, AppSec remediation posture, Veracode results, and secure SDLC maturity narrative. The work translated technical security improvements into customer-facing proof that supported a major enterprise deal and strengthened Splunk's broader product-security credibility.

Client
Splunk Inc.
Engagement Type
Full-Time
Period
2014–2015
Role
Senior Product Security Engineer
Focus Areas
Product Security Program Buildout, Secure Software Development Lifecycle, Risk Management and Vulnerability Management
The Context
Splunk is a leading data platform that powers critical security, observability, and IT operations for global enterprises. As the product portfolio expanded and customer security expectations increased, Splunk needed a strong, measurable, and scalable product security function to reduce risk and accelerate secure innovation.
The Challenge
Product security efforts were distributed, inconsistent, and reactive. The organization needed stronger program foundations, clearer risk visibility, better engineering adoption, and enterprise-grade evidence to meet customer and regulatory expectations.
What I Did
Built the product security function from the ground up and established the operating model, processes, tooling, and culture required to scale securely.
The Outcome
Transformed product security into a strategic, measurable, and trusted function that improved the security posture of Splunk's platform and enabled faster, safer delivery.
70%+
Reduction in high and critical findings over time
100%
Secure SDLC adoption across participating engineering teams
3x
Increase in security coverage across key product areas
Enterprise
Customer evidence and security-answer capabilities
Faster
Security feedback loops and remediation cycles
Secure
SDLC and product-security maturity across 16 Splunk-built products and 450+ marketplace applications in the broader program scope
To
An app certification and review operating model that triaged or addressed 800+ substantive Splunkbase findings
Broader
Product-security evidence and tooling maturity that helped achieve a 100/100 Veracode result for a major enterprise deal
SAST
Results, vulnerability remediation, secure SDLC practices, and customer-facing security evidence
Enterprise
Customer-trust and deal-readiness workflows through product-security engineering and assurance artifacts
Key Deliverables
Collaboration
Worked closely with Engineering, Product Management, GRC, IT, Legal, and Executive Leadership to align security with business objectives and customer needs. Worked across product security, engineering, product management, sales engineering, leadership, and customer-facing stakeholders to make secure development practices repeatable, measurable, and useful for both engineering delivery and customer trust. Worked across product security, engineering, sales engineering, product management, leadership, customer-facing teams, and customer security stakeholders to convert real AppSec improvement into credible enterprise assurance.
Client
Splunk Inc.
Engagement Type
Full-Time
Period
2014–2015
Role
Senior Product Security Engineer
Focus Areas
Product Security Program Buildout, Secure Software Development Lifecycle, Risk Management and Vulnerability Management
The Context
Splunk is a leading data platform that powers critical security, observability, and IT operations for global enterprises. As the product portfolio expanded and customer security expectations increased, Splunk needed a strong, measurable, and scalable product security function to reduce risk and accelerate secure innovation.
The Challenge
Product security efforts were distributed, inconsistent, and reactive. The organization needed stronger program foundations, clearer risk visibility, better engineering adoption, and enterprise-grade evidence to meet customer and regulatory expectations.
What I Did
Built the product security function from the ground up and established the operating model, processes, tooling, and culture required to scale securely.
The Outcome
Transformed product security into a strategic, measurable, and trusted function that improved the security posture of Splunk's platform and enabled faster, safer delivery.
70%+
Reduction in high and critical findings over time
100%
Secure SDLC adoption across participating engineering teams
3x
Increase in security coverage across key product areas
Enterprise
Customer evidence and security-answer capabilities
Faster
Security feedback loops and remediation cycles
Secure
SDLC and product-security maturity across 16 Splunk-built products and 450+ marketplace applications in the broader program scope
To
An app certification and review operating model that triaged or addressed 800+ substantive Splunkbase findings
Broader
Product-security evidence and tooling maturity that helped achieve a 100/100 Veracode result for a major enterprise deal
SAST
Results, vulnerability remediation, secure SDLC practices, and customer-facing security evidence
Enterprise
Customer-trust and deal-readiness workflows through product-security engineering and assurance artifacts
Key Deliverables
Collaboration
Worked closely with Engineering, Product Management, GRC, IT, Legal, and Executive Leadership to align security with business objectives and customer needs. Worked across product security, engineering, product management, sales engineering, leadership, and customer-facing stakeholders to make secure development practices repeatable, measurable, and useful for both engineering delivery and customer trust. Worked across product security, engineering, sales engineering, product management, leadership, customer-facing teams, and customer security stakeholders to convert real AppSec improvement into credible enterprise assurance.
At a Glance
Focus Areas
Tools & Technologies
Evidence & Artifacts
Public-Safe Caveat
This case study uses conservative public-safe language. Specific internal metrics, program details, team structures, customer names, internal artifacts, and confidential information have been generalized or omitted. This case study uses conservative public-safe language based on uploaded resume/profile/project context and prior portfolio source material. Exact internal scorecards, vulnerability records, product-specific findings, customer identities, proprietary review criteria, and non-public remediation details are omitted. This case study uses conservative public-safe language based on uploaded resume/profile/project context and prior portfolio source material. Exact customer identity, deal value, Veracode report details, private findings, remediation tickets, internal communications, and proprietary security artifacts are omitted.
David Wolf
AI Security · Product Security · Security Leadership
Based on analyzed public signals, not proof of any individual's or company's internal state.