Andrew Hamilton

Andrew is a Principal Security Consultant with Veracode focusing his time on web and mobile application penetration testing. Andrew has a broad base of experience with language from C, ColdFusion, Java, Flex (Action Script) and JavaScript and mobile application development. His development experience included building automation on Ant, Hudson and later the Jenkins platforms. Andrew is an active participant in his local ISC2 and ISSA chapters and presents occasionally to both. He holds active CISSP and GWAPT certifications. Andrew enjoys penetration testing and strives to provide maximum value to his clients. In his personal time, Andrew enjoys practicing Brazilian Jiu Jitsu.
Posts by Andrew Hamilton

Surviving a Password Policy Perfect Storm

December 27, 2016  | Intro to AppSec

As a security consultant, I see examples all the time of applications that don’t implement defense-in-depth to reduce the risk of account compromises. One area where this is especially problematic is password policy. Password policies can contribute to a strong application security strategy, or create a false sense of security while leaving user data and applications open to attack. Weak policies... READ MORE

Love to learn about Application Security?

Get all the latest news, tips and articles delivered right to your inbox.

 

 

 

contact menu