$ whoami

Cameron Woodward

Senior Security Engineer

I secure the software supply chain at enterprise scale. At Capital One I run the SDLC security gate that decides which container images ship, scanning millions of production containers every day and blocking non-compliant builds before they reach production.

Portrait of Cameron Woodward
  • Millionsof production containers scanned daily
  • 62%faster enterprise container scans (4 min to 1.5 min)
  • 100%scan coverage after re-architecting the scan scheduler
  • 2Fortune 200 companies (Capital One + Discover) unified on one scanning platform

About

I'm a security engineer with 5+ years hardening AWS cloud infrastructure and enforcing security controls across the software delivery lifecycle. My work sits where cloud infrastructure, containers, and the release pipeline meet: AWS IAM and S3, container and Kubernetes security, and SDLC scan-gate controls that stop non-compliant releases before they're deployed.

I came up through software engineering, which shapes how I do security. I build the scanning platforms, pipelines, and APIs myself, and I care about test coverage, reliability, and developer experience as much as findings. My background also includes applied cryptography, from mapping PGP keys to threat actors in dark web investigations, and leading security programs that span multiple organizations.

Next, I'm starting an M.S. in Computer Science (AI specialization) at Georgia Tech in January 2027. Long term, I want to help lead the field of AI-driven security.

Featured work

Capital One · Open source

VulnHunter

I contributed to VulnHunter, Capital One's open-source vulnerability scanner. It pairs SAST-style code analysis with chained-attack (DAST-like) detection to surface multi-step exploit paths that single-finding scanners miss.

  • SAST
  • Attack chains
  • Open source
github.com/capitalone/vulnhunter

Capital One + Discover · Program leadership

Unifying vulnerability scanning across Capital One and Discover

After Capital One's acquisition of Discover Financial Services, I directed the strategic integration of both companies' container and image vulnerability scanning platforms onto a single unified system. Merging two Fortune 200 security programs, we reached full compliance ahead of a federal deadline.

  • Vulnerability management
  • Compliance
  • Cross-org leadership

Capital One · Supply chain security

Enterprise container release gate

I operate the SDLC security gate that governs container release decisions across the enterprise. It scans thousands of images in the artifact registry and millions of running containers daily, and blocks non-compliant builds before deployment.

  • Container security
  • SDLC controls
  • AWS

Capital One · Platform engineering

Faster, fully covered scanning pipeline

I re-engineered the registry scanning pipeline, cutting average scan time by 62%. Then I architected a scheduler and redrive Lambda system with dead-letter-queue reprocessing that achieved 100% scan coverage, and I raised automated test coverage from 71% to 100%.

  • AWS Lambda
  • SQS / DLQ
  • Reliability

Experience

  1. Security Engineer II @ Capital One

    to present · McLean, VA

    • Operate the SDLC security gate governing container release decisions enterprise-wide. It scans thousands of container images across the artifact registry and millions of containers across production workloads daily, and blocks non-compliant builds before deployment.
    • Directed the strategic integration of container and image vulnerability scanning platforms across two Fortune 200 organizations, Capital One and Discover Financial Services, onto a unified system, achieving full compliance ahead of a federal deadline.
    • Re-engineered the enterprise registry scanning pipeline architecture, cutting average container scan time 62% (4 min to 1.5 min) across all company-wide scans.
    • Architected a scheduler and redrive Lambda system with dead-letter-queue reprocessing, achieving 100% scan coverage while raising automated test coverage from 71% to 100%.
    • Contributed to VulnHunter, Capital One's open-source vulnerability scanner that combines SAST-style code analysis with chained-attack detection.
    • Deployed Wiz runtime security sensors across containerized Fargate workloads, engineering the integration and delivering full unit and acceptance test coverage.
    • Led resolution of high-severity production incidents, including a full scanning-platform outage. I coordinated the cross-team response and executive communication, and service was restored the same day.
    • Built Java and Go APIs powering B2B virtual card payment creation, and led a company-wide Java 8 to 17 migration across production services.
  2. Software Developer @ CGI Federal

    to · Fairfax, VA

    • Architected a financial planning and tracking application for a federal agency, integrating custom C# plug-ins with Microsoft Power Platform to streamline budgetary reporting.
    • Automated infrastructure provisioning with Puppet Bolt and resolved production issues through root-cause incident analysis, improving deployment reliability.
  3. Software Developer Intern @ Bluestone Analytics

    to · Charlottesville, VA

    • Built Python web scrapers and AWS S3/Kibana data pipelines supporting federal cybercrime investigations into dark web threat activity.
    • Applied public-key cryptography, parsing PGP keys with the PGPy library and mapping them to threat actor identities to support attribution in active investigations.

Skills

Security focus

  • AWS Cloud Security
  • Container & Kubernetes Security
  • Vulnerability Management
  • SDLC Security Controls
  • SAST / DAST
  • Applied Cryptography

Cloud & security tooling

  • AWS
  • Qualys
  • Wiz
  • AquaSec
  • Checkmarx
  • Docker
  • Kubernetes
  • Fargate
  • JFrog Artifactory
  • Jenkins
  • Splunk
  • New Relic

Practices

  • CI/CD Pipeline Security
  • IAM & Secrets Management
  • Secure SDLC
  • OWASP Top 10
  • Threat Modeling
  • Incident Response
  • Agile / SAFe

Languages

  • Python
  • Go
  • Java
  • Bash
  • C++
  • C#
  • SQL

Education & certifications

M.S. Computer Science, AI Specialization

Georgia Institute of Technology

Starting January 2027 · Part-time alongside full-time work

AWS Certified Solutions Architect – Associate

Amazon Web Services

SAFe 6 Scrum Master

Scaled Agile

Outside work

I've been to 42 states and 15 countries and I'm still counting. When I'm home, you'll find me snowboarding, playing tennis, kayaking, camping, cooking (a skill my grandmother taught me), or at the gym.

I also built a few browser games for fun: Tower Stack, Dino Jumper, and Snake.

Contact

I'm always happy to talk about container security, cloud security, or where AI and security are headed. Email is the best way to reach me.

cameronwoodward0@gmail.com

Or find me on LinkedIn and GitHub.