Fictional resume example. Names, employment histories and results are illustrative, not an actual employee record.
Claire Morgan
Security Engineer with experience in risk reduction, detection, response, and secure systems. Practical work includes Threat modeling, Detection engineering, Incident response, Cloud security.
Experience
OpenAI
Seattle · United States
Security Engineer
Mar 2022 - now
- Performed threat modeling for account recovery and session renewal, tracing trust boundaries and abuse paths. Turned the findings into application security controls and negative authorization tests before release.
- Used Python to reproduce authorization vulnerabilities during scoped penetration testing in an approved test environment. Paired each finding with a failing request, a code fix, and a regression test that confirmed the bypass was closed.
- Correlated an application finding with the affected endpoint and authorization path, reproduced the exploit in a test environment, and retested both the fix and adjacent access controls.
- Owned an application-security review using threat modeling and authorized penetration testing, resolving an authorization bypass before the affected endpoint was released.
- Built Python regression checks for the patched access path and verified encryption settings, enabling reviewers to reproduce both the blocked attack and legitimate request.
Cisco
San Jose · United States
Security Engineer
Jan 2019 - Feb 2022
- Ran two incident simulations with engineering, legal, and support. Kept turnaround time within the agreed operating window.
- Reviewed remediation evidence against the original finding, retested the affected access path, and kept residual exposure visible when the mitigation could not remove the entire risk.
- Reconstructed an access incident from authentication logs and the affected account’s permissions, distinguished authorized service activity from unexpected access, and verified containment with the service owner before revoking temporary restrictions.
Selected project
Security Engineer — independent case study
Project owner
Feb 2024 - Jun 2024
- Automated evidence collection for 12 access-control checks
- Built a lab assessment using synthetic accounts and a published control framework; mapped each finding to the affected access path and kept evidence of both the vulnerable and remediated state.
- Retested the proposed control with an authorized negative case and wrote a residual-risk note; distinguished a passed laboratory check from assurance about an organization’s entire environment.
- Owned the authorized lab retest using synthetic accounts, resolved an access-control gap and completed a report showing both the blocked request and the permitted path.
Education
University of Washington
Seattle, Washington · United States
B.S. Computer Science
Sep 2013 - Jun 2017
Relevant coursework: Algorithms, operating systems, databases, computer networks
Skills
Role expertise
Threat modeling · Detection engineering · Incident response · Cloud security · Python · IAM
Certifications
CompTIA Security+
CompTIA
Jun 2024
Publications
- Published an independent security note using redacted lab evidence, distinguishing a verified control from residual risk and explaining why a passed test is not whole-system assurance.


