ZL/APP Dev/SEC Hire →
DOSSIER / 2026 CLASS: SR. APPSEC ENGINEER ● STATUS: OPEN TO ROLES

Zachary
Lewis.

I build and break software. Thirty years shipping production code, a decade hardening it. Now building AI-powered tools that turn threat intel into runbooks developers actually use

Summary
NAMEZ. LEWIS
ROLEFull Stack, Cyber APPSEC ENG.
YRS30+
CERTCISSP
CERTCSSLP
REMOTE✓ YES
OPEN TO RELOCATE✓ YES

Application Security Engineer / Senior Full Stack Developer / AI Security Builder / Founder of Zactonics AI.

Currently translating OWASP ASVS, MITRE ATT&CK, and CVE feeds into browser-native tools that live next to the developer — not on a dashboard they'll never open.

CISSP OWASP ASVS Threat Modeling MITRE ATT&CK CSSLP DevSecOps AI-SPM MCP Hardening Prompt Injection Defense SAST / DAST / SCA Zero Trust Keycloak + OIDC CISSP OWASP ASVS Threat Modeling MITRE ATT&CK CSSLP DevSecOps AI-SPM MCP Hardening Prompt Injection Defense SAST / DAST / SCA Zero Trust Keycloak + OIDC
§ 00 / Brief
i.

I live at the seam where code is written and where attackers get in.

My career started in 1991 building financial systems at Nationwide, then moved through IBM, Unisys, and a decade as an Application Security SME at Micro Focus and Telos — running Fortify SCA, AppScan, and secure-code training for Fortune 500 and federal programs.

Since 2020 I've led full stack and security engineering at Clarity Innovations — embedding threat modeling and SAST/SCA into CI/CD, architecting Keycloak + OIDC identity platforms, and shipping AI platforms with prompt-injection guardrails and RAG access controls aligned to the OWASP Top 10 for LLMs.

In 2024 I founded Zactonics AI to build what I kept wishing existed: tools that read an architecture and a CVE feed and produce something a developer can actually ship — runbooks, remediation plans, regression tests for prompt injection, MCP audit reports.

I mentor engineers. I sit on the board of the Children's Museum of Montgomery. I tutor adult literacy. I led Meta's Developer Circle in Montgomery for five years. The best security work I've done has always been about getting humans and systems to trust each other a little more carefully.

30+
Years shipping code
11
Live Zactonics apps
2
Senior Security Certs
CVEs still to triage
§ 01 / Selected Work

Featured builds.

Browser-native, privacy-first tooling. Most run entirely client-side — no server, no telemetry, architecture and CVE data never leave the device.

/ 03 Identity

Azure AD + Keycloak Federation — with RBAC & SSO

End-to-end enterprise identity documentation: Azure AD as IdP, Keycloak as broker, role- and cell-level authorization, and production hardening checklist.

OIDCSAMLRBAC/ABACZero Trust
/ 04 Platform

Temporal Build Flows

Visual durable-workflow designer demonstrating Temporal best practices, retry policies, and compensations for resilient enterprise pipelines.

TemporalWorkflowsResilience
/ 05 Security

Zero Trust Explained

Interactive walkthrough of Zero Trust architecture fundamentals — network segmentation, identity-centric controls, and continuous verification.

Zero TrustmTLS
/ 06 AppSec

App Rate Limiting Guide

Practical playbook for rate limiting patterns — token bucket, sliding window, distributed coordination, and abuse-prevention strategies.

API SecurityOWASP
/ 07 Product

SecureDoc Portal

Location-aware document search that bridges physical assets and digital files across multiple sites. Replaces messy folders with a real index.

RAGSemantic Search
/ 08 AI

AI for Business Decisions

Tooling that turns unstructured business input into structured, auditable decisions — with explainability and source-traceability baked in.

LLMExplainability
/ 09 AI Tooling

AI Agent Builder

Visual scaffolder for agentic workflows with a focus on safe tool-calling, guardrails, and containment patterns.

AgenticMCP
/ 10 Platform

Workforce Development Platform

Full-stack demo platform for skills matching, program management, and workforce analytics — built for state and regional workforce agencies.

Full StackAnalytics
/ 11 DevTool

Custom Diagram App

Drag-and-drop flow charts and state diagrams with auto-layout, snap-to-grid, and PNG / SVG / Mermaid export. Built because every other tool is overkill.

SVGMermaid
§ 02 / Currently Brewing
ii.
§ 03 / Timeline
iii.

Three decades, one throughline.

Financial systems → enterprise platforms → application security → AI security. The stack changes; the posture doesn't.

2024 — NOW Founder

Founder & Principal Engineer — Zactonics AI

Building AI-powered AppSec & resilience tooling. Shipped the Resilience Plan + Runbooks generator; designed stack→ATT&CK→ASVS knowledge packs; architected a fully browser-native pipeline so customer architecture never leaves the device.

2020 — NOW Sr. Full Stack & SWE Manager

Clarity Innovations, LLC

Embedded secure SDLC across React/Java/Python services — SAST/SCA in CI/CD, OWASP ASVS enforcement, code review on injection and supply-chain risk. Architected Keycloak + OIDC identity with RBAC/ABAC and mTLS. Built an AI platform with LangChain + ChromaDB + Spark, hardened against the OWASP LLM Top 10. Led and mentored the engineering team.

2012 — 2020 Solutions Architect & AppSec Consultant

Micro Focus

Application security consulting for Fortune 500. Operationalized Fortify SCA, IBM AppScan, and SCA tooling at enterprise scale. Threat modeling and secure code review across Java, Python, React, C/C++, Kotlin, Ruby, and SAP ABAP codebases.

2010 — 2012 AppSec Solutions Engineer

Telos Corporation

Federal and enterprise AppSec — Fortify SCA and AppScan for SAST/DAST/remediation triage. Led secure-coding training covering OWASP Top 10, NIST 800-53, and FISMA.

2007 — 2010 Performance & Availability Consultant

Unisys

Performance engineering, capacity planning, and business-availability work across Java, C/C++, and Solaris for government and commercial clients — with resilience baked into the SDLC.

1999 — 2001 Software Engineer

IBM

Enterprise software engineering across IBM's development org — large-scale distributed applications with strong emphasis on reliability and code quality.

1991 — 1998 Software Engineer — Strategic Initiatives

Nationwide Insurance

Full-stack development on business-critical financial-services systems. Systems reliability, database engineering, and cross-team delivery — where the craft started.

§ 04 / Toolkit
iv.

The stack.

Application Security

OWASP Top 10 & ASVS · Threat Modeling · SAST / DAST / SCA / IAST · Secure SDLC · DevSecOps · Fortify SCA · IBM AppScan · Snyk · Semgrep · CodeQL · Burp Suite · SBOM · MITRE ATT&CK · CVE Management · CIS Benchmarks

AI Security

OWASP Top 10 for LLMs & Agentic AI · Prompt Injection Defense · AI Red Teaming · AI-SPM · Model Context Protocol (MCP) Hardening · RAG Pipeline Security · Vector DB Controls · AI-BOM · LangChain Guardrails · NIST AI RMF · ISO 42001

Frontend

React · Next.js · Node.js · Angular · JavaScript / TypeScript · HTML5 / CSS3 · Tailwind · Responsive Design

Backend

Java / Spring Boot · Python / Flask / FastAPI · Elixir · Go · Rust · C# / .NET · Ruby on Rails

Data & APIs

PostgreSQL · MySQL · MongoDB · Redis · ChromaDB · Apache Iceberg · REST · GraphQL · gRPC · WebSockets · Event-Driven Architecture · OAuth 2.0 / OIDC

DevOps & Cloud

Docker · Kubernetes · GitHub Actions · Jenkins · Terraform · AWS · Azure · GCP · Secure CI/CD Pipelines · Image Scanning · Signed Artifacts

Identity & Access

Keycloak · OAuth 2.0 / OIDC · SAML · RBAC / ABAC · Zero Trust · mTLS · Secrets Management

AI / ML

LangChain · OpenAI / Anthropic / Claude APIs · RAG · Semantic Search · Apache Spark · Multimodal Pipelines · Prompt Engineering

CERTIFICATION
CISSP
Certified Information Systems Security Professional
CERTIFICATION
CSSLP
Certified Secure Software Lifecycle Professional
DEGREE
B.S. Computer Science
Washington Adventist University (Columbia Union College)
§ 05 / Off the clock

Community & mentorship.

2024 — PRESENT

Board Member

Children's Museum of Montgomery — shaping science, art, and technology programming for kids across central Alabama.

2025 — PRESENT

Adult Literacy Tutor

Capital Area Adult Literacy Council — one-on-one reading and GED preparation work.

5 YEARS

Meta Developer Circle Lead, Montgomery

Designed and delivered workshops, hackathons, and STEAM programs for regional developers.

ONGOING

Microsoft Developers Clubhouse Admin

Community leadership and technical education programming for local developers.

§ 06 / Closing

Let's build something worth trusting.

Remote-first. Open to Relocation. Based in Alabama. Looking for senior AppSec, AI Security, or staff-level full stack roles where security is engineering, not paperwork.