
Clayton Ingmire
Verified Expert in Engineering
Security Engineer and Developer
Oklahoma City, United States
Toptal member since July 21, 2026
Clayton is a senior product security engineer with 6+ years of experience blending software engineering and a security mindset. He architects and implements secure web and distributed systems, utilizing AWS, Kubernetes, and microservices patterns. He drives secure-by-design initiatives through resilient systems, hardening complex environments, and coaching developers to adopt an offensive mindset. His goal is to close the AppSec knowledge gap and embed security natively into the SDLC.
Portfolio
Experience
- Software Development - 15 years
- OWASP - 10 years
- Web Application Security (Web AppSec) - 8 years
- Software Architecture - 7 years
- Secure Code Best Practices - 7 years
- Application Security - 7 years
- Applied Cryptography - 7 years
- Vulnerability Remediation - 7 years
Preferred Environment
AWS IoT, Kubernetes, Docker, Splunk, Grafana, Git, Composer, BrowserStack
The most amazing...
...security program I've led is the red-team penetration testing initiative at Pegasystems, which directly improved cloud defenses across AWS-hosted Kubernetes.
Work Experience
Senior Software Developer, Logins and Security
Paycom
- Architected and refactored complex legacy monoliths into secure, containerized microservices and React SPAs, significantly enhancing maintainability and hardening defenses to strict OWASP standards.
- Redefined architectural requirements for enterprise password recovery systems to proactively remediate critical security shortcomings, dramatically improving the reliability and defensive posture of authentication flows.
- Integrated large language models (Claude, Gemini, local LLMs) into the development workflow, drastically accelerating root-cause analysis (RCA) for complex bugs and optimizing remediation strategies for edge-case vulnerabilities.
- Mentored cross-functional development teams on secure coding best practices, cultivating an offensive security mindset to preemptively identify and mitigate software vulnerabilities.
- Engineered highly resilient internal tooling that seamlessly integrated into existing development workflows and reduced workflow process deviations by approximately 10-15%.
Senior Cloud Security Engineer
Pegasystems
- Engineered core security algorithms and executed rigorous manual code reviews, providing the architectural guidance necessary to harden enterprise Java applications against advanced threats.
- Evaluated cloud infrastructure architectures for design flaws and security misconfigurations using automated tools (e.g., kube-hunter), directly remediating cryptographic key lifecycle vulnerabilities and recommending architectural improvements.
- Spearheaded red-team penetration testing across AWS-hosted Kubernetes and legacy EC2 environments, translating complex security audits into engineering-focused remediation requirements for development teams.
- Conducted rapid-response vulnerability risk assessments for critical zero-days (e.g., Log4Shell) and performed software composition analysis (SCA), presenting high-level threat models directly to executive leadership.
- Researched emerging AI security frameworks, including the OWASP Top 10 for LLMs, to proactively integrate AI security considerations into baseline adversarial threat modeling and system architectures.
- Directed 3rd-party vulnerability management, administering the CVE reporting program and assigning precise CVSS scores to effectively triage vulnerabilities within engineering backlogs.
Application Security Analyst
Paycom
- Identified and developed remediations for hundreds of security vulnerabilities, strategically aligning robust security protocols with overarching business velocity and organizational priorities.
- Engineered custom Python/Flask microservices to aggregate SAST/DAST telemetry, real-time remediation statuses, and analyst feedback, significantly streamlining analysts' workflows and improving total remediation times by approximately 30%.
- Architected an automated Dynamic Application Security Testing (DAST) tool that seamlessly integrated into low-level application kernel bootstrapping routines, mapping all module configurations within the monolith to identify dozens of instances of.
- Designed the foundational data model and algorithmic logic for a novel proof-of-concept PHP OpCode analysis tool, successfully demonstrating the technical viability of integrating deep-level vulnerability detection into automated workflows.
- Directed cross-functional architectural overhauls and strategic security initiatives, serving as a dedicated security mentor to foster secure coding practices across engineering teams.
Software Engineering Intern
Kalidy LLC
- Developed full-stack web applications utilizing the Laravel framework and Vue.js to deliver responsive, user-centric features.
- Developed a custom employee time tracking web application as a part of a broader effort to digitize physical processes.
- Managed routine database administration tasks and contributed to front-end web design initiatives.
Experience
Demo Go RESTful Event Management Web App
https://github.com/ClaytonIngmire/demo-go-events-rest-appEducation
Bachelor's Degree in Computer Science
University of Oklahoma - Norman, Oklahoma, USA
Diploma in Economics and Computer Science
Oxford University - Oxford, UK
Certifications
AWS Certified Solutions Architect – Associate
Amazon Web Services
Certified Information System Security Professional (CISSP)
ISC2
GIAC Web Application Penetration Tester (GWAPT)
GIAC
Skills
Libraries/APIs
Auth, React, Vue
Tools
Splunk, Git, Composer, BrowserStack, NGINX, NPM, NMap, Sqlmap, DirBuster, Metasploit, AWS CloudFormation, Grafana, Apache, Artifactory, Gradle, Helm, Terraform, PhpMyAdmin
Languages
Python, PHP, Java, Go, SQL, JavaScript, TypeScript, C, C++, C#.NET, SAML, Ruby
Paradigms
Penetration Testing, Secure Code Best Practices, Role-based Access Control (RBAC), Automation, Software Testing
Storage
MySQL, NoSQL, MongoDB, Redis
Industry Expertise
Cybersecurity
Frameworks
Flask, Laravel, OAuth 2, Spring Boot, Angular
Platforms
Docker, AWS IoT, Kubernetes
Other
OWASP, CVSS, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), OWASP Top 10, Software Development, Secure Software Development Lifecycle (SSDLC), Vulnerability Remediation, Code Review, Risk Management, Web Application Security (Web AppSec), Secure Web Development, Application Security, Vulnerability Assessment, IT Security, Security, Reporting, Reports, Security Audits, Vulnerability Management, Security Engineering, MITRE ATT&CK, Nikto, Artificial Intelligence (AI), Applied Cryptography, Econometrics, Software Architecture, Security Management, System Design, RESTful Microservices, IIS, Economics, Auditing, SecOps, Endpoint Protection, IDS/IPS, Proxies, System Administration, Security Monitoring, Network Security, AI Agents, AI Security, Large Language Models (LLMs), AI Trust, Risk and Security Management (AI TRiSM), Prompt Injection, Agentic AI, SOC 2 Compliance, Red Teaming, OpenID Connect (OIDC), Compliance, SOC 2
How to Work with Toptal
Toptal matches you directly with global industry experts from our network in hours—not weeks or months.
Share your needs
Choose your talent
Start your risk-free talent trial
Top talent is in high demand.
Start hiring