Application Security Tester @ OnDefend
Iβm Malik Smith, an Application Security Engineer specializing in application security testing, secure code review, static analysis, mobile and web application security, and DevSecOps automation. I work closely with development teams to identify, validate, and remediate security vulnerabilities throughout the Secure Software Development Lifecycle (SSDLC), helping organizations deliver resilient, secure applications at scale.
My experience spans manual application penetration testing, secure design reviews, custom SAST rule development, vulnerability management, and security automation. Iβve worked with commercial and government organizations, supporting security assessments for modern mobile and web applications while developing automation that streamlines vulnerability detection, validation, and remediation.
Iβm passionate about building security into the development process through custom static analysis, CI/CD security integrations, Infrastructure-as-Code (IaC) security, and developer-focused security tooling. Personal projects such as MobileMorphAgent and BluJay reflect my interest in combining offensive security techniques with scalable security engineering solutions that improve efficiency without sacrificing security.
My long-term goal is to become a Principal Vice President and ultimately a Chief Information Security Officer (CISO) by combining deep technical expertise with security leadership, cloud security, AI security, and secure software engineering.
Application Security
- Secure Code Review
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Software Composition Analysis (SCA)
- Threat Modeling
- Vulnerability Assessment & Risk Analysis
- Secure Software Development Lifecycle (SSDLC)
Offensive Security
- Mobile Application Penetration Testing (Android & iOS)
- Web Application Penetration Testing
- API Security Testing
- OWASP Top 10
- OWASP API Security Top 10
- OWASP MASVS & MSTG
Security Engineering & DevSecOps
- Security Automation
- Custom Semgrep & CodeQL Rule Development
- CI/CD Security Integration
- GitHub Actions
- Jenkins
- GitLab CI/CD
- Infrastructure-as-Code (IaC) Security
Cloud & Platform Security
- AWS Security Fundamentals
- Container & Dependency Security
- Vulnerability Management
- Secure Configuration Reviews
Tools & Technologies
- Semgrep
- CodeQL
- Coverity
- Burp Suite Pro
- MobSF
- Frida
- Ghidra
- JADX
- OWASP ZAP
- Docker
- GitHub
- GitLab
- Jenkins
- CEH β EC-Council Certified Ethical Hacker v12
- Foundation Level Cyber Threat Intelligence β arcX
- Static Analysis & Code Security Specialization β Semgrep, CodeQL, custom rule development, taint tracking, CI/CD integration, and secure code review automation
- Q3 2026 PMPA β TCM Security's Practical Mobile Pentest Associate (in progress)
- Q4 2026 PAPA β TCM Security's Practical AI Pentest Associate (in progress)
Strengthen expertise in application security, secure software development, mobile security, AI security, and DevSecOps to position for Senior Application Security, Product Security, and DevSecOps Security Engineer roles.
- Q1 2027 IAPP AIGP - Artificial Intelligence Governance Professional
- Q2-Q3 2027 CISM β Certified Information Security Manager (ISACA)
- Q4 2027-Q1 2028 CISSP β Certified Information Systems Security Professional (ISCΒ²)
Combine deep technical expertise with security governance and leadership to prepare for Principal Security Engineer, Security Architect, and technical leadership opportunities.
- MS in Cybersecurity Operations - Projected Graduating Class Fall 2028
- Focus Areas:
- Security Leadership
- Goverance & Risk Leadership
- Cloud & Enterprise Security
- Cyber Operations
- Security Program Management
- Focus Areas:
Complements advanced technical certifications with leadership, business, and strategic decision-making skills.
*By 2030, develop a well-rounded background spanning:
- Application Security
- Product Security
- DevSecOps
- Cloud Security
- AI Security
- Security Leadership & Governance
Career Goal:
- Principal Application Security Engineer
- Security Architect
- Director of Application Security
- Chief Information Security Officer (CISO)
- CEO of my own Tech Consulting/Contracting Firm
| Domain | Certifications |
|---|---|
| AppSec/DevSecOps & Automation | CSSLP, Semgrep, CodeQL, Custom SAST Rules |
| Mobile App Security | PMPA |
| AI Security | PAPA |
| Cloud Security | AWS Certified Security-Specialty |
| Threat Intelligence | arcX CTI Foundation |
| Leadership & Governance | CISM, CISSP |
| Secure Development | CSSLP, CI/CD Security, Threat Modeling |
| Security Automation | Custom SAST Rules, DevSecOps, CI/CD Integration |


