Nina Patel
nina.patel@example.com+44 20 7946 0136linkedin.com/in/ninapatelgithub.com/ninapatel
Summary
Security engineer with 8 years protecting web applications, cloud infrastructure, and identity systems.
Experienced in application security reviews, threat modelling, vulnerability management, IAM, secure SDLC, incident response, and developer enablement.
Experience
Senior Security Engineer
CivicCloud | London, UK | February 2021 - Present
- Lead application security reviews for 24 product teams shipping citizen-facing digital services.
- Built threat modelling programme that covered 78 high-risk services and reduced late-stage security findings by 44%.
- Implemented SAST, dependency scanning, and secret scanning in CI, blocking 320 high-risk issues before production.
- Designed AWS IAM guardrails and least-privilege patterns that reduced admin access by 63%.
- Mentor engineers through secure design reviews, vulnerability triage, and incident follow-up.
Security Engineer
FinGate | Manchester, UK | June 2017 - January 2021
- Managed vulnerability triage for payment systems, reducing critical remediation SLA misses from 18% to 3%.
- Built detection rules for credential stuffing, account takeover, and suspicious API usage.
- Led OAuth and SSO hardening across 9 customer-facing applications.
- Investigated security incidents with logs, packet captures, endpoint telemetry, and post-incident actions.
Application Security Analyst
SecureNorth | York, UK | September 2015 - May 2017
- Performed web application testing across OWASP Top 10 risks for finance and retail clients.
- Wrote remediation guidance that helped engineering teams close 86% of high findings within 30 days.
- Automated report generation and evidence capture, saving consultants 12 hours per engagement.
- Delivered secure coding workshops to 140 developers across JavaScript, Java, and Python stacks.
Skills
Security
Application security, Threat modelling, OWASP Top 10, Vulnerability management
Cloud
AWS IAM, Kubernetes security, Container scanning, Terraform
Detection
SIEM, Sigma, CloudTrail, EDR, Incident response
Tools
Burp Suite, Semgrep, Snyk, GitHub Advanced Security, Splunk
Education
- BSc Cyber Security, Lancaster University
- CISSP, AWS Security Specialty