Hello! 👋

I'm Nathan Getty

Lead Security Engineer

About Me

Security platform engineer with 10+ years in infrastructure security, specializing in automating security services. I design automated security systems for multi-cloud environments and turn third-party security tools into scalable, developer-friendly platforms. Strong software engineering foundation in Python, Infrastructure as Code, and cloud-native architecture (GCP, AWS) — with a track record of reducing operational toil through automation while enabling engineering teams to move fast without compromising security. Now working at the intersection of security and AI. I build the infrastructure that lets AI tools operate safely inside the enterprise — secure agent integrations (MCP), AI-driven detection and triage, and privacy-preserving telemetry pipelines — and I research how AI workflows get attacked, from prompt injection to data exfiltration.

Python Terraform GCP AWS Azure Infrastructure as Code Serverless Docker Kubernetes SIEM / SOAR eBPF (Osquery, Uptycs) CI/CD Threat Modeling Cloud Security

Experience

Senior Security Engineer

Menlo Security Inc

Jan 2021 - Present
  • Architected cloud security infrastructure during an AWS-to-GCP migration: automated security guardrails, policy enforcement, and API-driven security services enabling secure-by-default deployments across thousands of endpoints.
  • Built an automated SOC platform using cloud native microservices with a normalized alert-ingestion API, token auth, context enrichment, and AI-driven triage — cutting false positives via quarterly prompt-optimization cycles.
  • Designed a production vulnerability-scanning platform that turned manual security operations into automated, API-driven self-service, reducing scan time from hours to minutes.
  • Manage Just-In-Time access platform across multi-cloud via Terraform, eliminating 90% of standing privileged access and cutting provisioning from up to 2 hours to 2-3 minutes.
  • Built internal security platform components — domain monitoring, vulnerability scanning APIs, and agent orchestration on eBPF tooling, plus reusable CI/CD catalog items (SAST/DAST/Vuln Scanning) enabling shift-left security.
  • Led threat modeling and security architecture reviews across AWS, GCP, and Azure, and drove SOC 2, FedRAMP (NIST 800-53), and CIS remediation through automated infrastructure changes.

Senior Cloud Security Engineer

Just Eat / SkipTheDishes

Dec 2019 - Jan 2021
  • Built a serverless security automation platform (CloudWatch Events, Lambda) for continuous monitoring, automated policy enforcement, and auto-remediation across AWS infrastructure.
  • Built an API-driven remediation framework letting development teams self-service security fixes via API Gateway, reducing security-team toil and unblocking engineering workflows.
  • Engineered pre-deployment security validation that blocked releases with critical misconfigurations, integrating automated security testing into CI/CD pipelines.
  • Partnered with engineering teams to design security guardrails, establishing shift-left security practices across the organization.

Senior Information Security Analyst

Wawanesa Mutual Insurance Company

May 2015 - Dec 2019
  • Architected and led a cloud security initiative: an AWS security automation framework with least-privilege access controls, automated account provisioning, and role-based access management.
  • Deployed a SOAR platform with API integrations for automated incident response, reducing mean time to contain and mitigate security risks across enterprise infrastructure.
  • Built an automated web-application security testing framework and conducted manual penetration testing for business-critical applications.
  • Deployed and integrated an enterprise security stack (SIEM, DLP, CASB, WAF) with internal tools and workflows.

Selected Work

01

AI-Native Tooling & Developer Integrations

Building the infrastructure that lets AI coding tools (Claude Code, Gemini CLI, and similar) safely interact with on-prem enterprise systems.

  • Developed and deployed a Model Context Protocol (MCP) server exposing a secure, streamable HTTP (SSE) interface to enterprise issue-tracking and wiki systems.
  • Added capabilities like watcher management and page creation/updates, with support for wiki markup, storage XML, and gzipped base64 streams for large payloads.
  • Integrated markup primers into tool descriptions to guide LLMs through non-standard formatting.
  • Built an AI plugin that automates SAST gap investigations and proposes and writes repo-specific Python matchers.
MCPLLM ToolingPythonSSE / HTTPSAST
02

Cloud Data Privacy & Telemetry Infrastructure

Designed a secure telemetry pipeline for Claude Code/Cowork usage that balances data-driven insight with strict privacy and compliance.

  • Built a custom OpenTelemetry collector packaged as a Kubernetes/Helm chart and deployed to managed Kubernetes (GKE).
  • Configured in-flight redaction processors that detect sensitive prompt logs and strip them before they leave the network.
  • Fanned out telemetry from a single pipeline to multiple destinations — log monitoring, engineering metrics, and an analytics warehouse.
  • Designed split-stream routing that stores raw, unredacted logs in a tightly restricted, security-owned bucket for forensics while keeping all downstream endpoints sanitized.
OpenTelemetryKubernetes / HelmGKEData Privacy
03

Continuous Vulnerability Management & SBOM Architecture

Architected a continuous-compliance and immutable release-tracking framework for production VM images.

  • Specified and built a distributed worker service (Cloud Run + Pub/Sub) that uses Syft to extract disk images offline and publish CycloneDX SBOMs to cloud storage.
  • Deployed OWASP Dependency-Track instance that continuously matches newly disclosed CVEs against existing SBOM catalogs without re-scanning live VMs.
  • Authored reusable CI/CD components that run Trivy and generate SBOMs as an enforced gate before container releases.
SBOMSyftCycloneDXDependency-TrackTrivy
04

Compliance, Host Security & Exceptions-as-Code

Manages compliance posture and endpoint-agent health across AWS and GCP host fleets.

  • Built an exceptions-as-code platform: compliance exception profiles version-controlled in YAML, peer-reviewed via merge requests, and applied automatically through pipelines.
  • Wrote a Python wrapper and systemd daemon deployed fleet-wide that configures and runs host-monitoring agents on boot by querying cloud instance metadata (IMDS).
Host SecurityFedRAMPPythonsystemdIaC
05

Infrastructure Security & Supply-Chain Automation

Maintains foundational security boundaries and automated update systems across development repositories.

  • Implemented secure just in time access flows bastion-to-database/instance administration routes.
  • Set up sweeping automated dependency and OS-package updates (Ubuntu, Go, Python, Node) across repos to keep a clean security footprint (Renovate).
  • Authored custom incident-response tooling (containment, volume snapshots, memory snapshots).
TerraformSpaceliftRenovateGoSupply-Chain Security

Talks & Research

02

From Dangling DNS to Cloud Takeover

WinniSEC, 2025. Research on subdomain-takeover vulnerabilities in cloud environments, demonstrating how dangling DNS records pointing to cloud provider IPs can be exploited — plus an automated detection system (AWS Lambda + Step Functions) monitoring DNS records across multi-cloud infrastructure.

WinniSEC2025Cloud
03

Lessons from Security Companies: Managing Access in a Multi-Cloud World

Apono, 2025. Case study on implementing just-in-time (JIT) access management across multi-cloud infrastructure — reducing access provisioning time from hours to minutes while eliminating 90% of standing privileged access.

Apono2025JIT Access

Education

Diploma, Computer Networking

Red River College

2014
  • Major in Computer Networking
  • Cisco Certified Network Associate (CCNA)

Certifications & Training

SANS / GIAC

2016 - 2022
  • GIAC GWAPT - Web Application Penetration Tester (2017)
  • GIAC GCIA - Certified Intrusion Analyst (2016)
  • SANS SEC540 - Cloud & DevOps Security Automation (2019)
  • Advanced Programming with Python (2022)
  • SANS Advisory Board Member (2017)