Skip to content
View mattborja's full-sized avatar
πŸ”‘
Key IDs: A1C7E813F160A407, C8919DBCB39E6F72
πŸ”‘
Key IDs: A1C7E813F160A407, C8919DBCB39E6F72

Highlights

  • Pro

Block or report mattborja

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
mattborja/README.md

Matt Borja

Senior Software Engineer & Solution Architect
GIAC Advisory Board Member

🌐 mattborja.dev β€’ πŸ”¬ ORCiD β€’ πŸ’Ό LinkedIn

About

Senior Software Engineer and Solution Architect with extensive expertise in identity verification, cloud security, and scalable systems. Recognized industry expert and GIAC Advisory Board Member specializing in identity assurance, digital signatures, and Web of Trust principles aligned with NIST SP 800-63A.

Leadership spans high-availability infrastructure projects, research and development, identity and access management (IAM), and advanced DevOps practices. Proven expertise in designing secure, innovative solutions including Single Sign-On (SSO), SAML 2.0 identity providers, and systems integrations (SIS, Salesforce, Canvas, Twilio).

Current Focus: Cloud security automation, identity assurance, and securing the software supply chain.

Featured Project

SIG3 - High Identity Assurance Registry

Website GitHub

A Rapid Identity Assurance Level (RIAL) framework producing the highest level assurance for signing keys through a rigorously vetted, continuously delivered registry of identity proofs. Aligned with NIST SP 800-63A Digital Identity Guidelines.

Research Areas: Identity Assurance β€’ Digital Identities β€’ Digital Signatures β€’ Web of Trust β€’ NIST SP 800-63A

Related Work:

Recognition & Advisory Roles

2025

πŸŽ–οΈ GIAC Advisory Board Member
SANS Institute | Invited based on exceptional GCSA certification exam performance

πŸ›‘οΈ REN-ISAC Member
Research and Education Networks Information Sharing and Analysis Center | Sponsored by Higher Education CISO (May 2025)

πŸ” Security Researcher Hall of Fame
Ellucian | Responsible disclosure of high severity security findings prompting immediate remediation

🎀 Industry Speaker
Center for the Future | Web of Trust: Securing the Software Supply Chain

Certifications

Year Credential Issuer Verification
2025 GIAC Cloud Security Automation (GCSA) SANS Institute (ANAB-accredited) πŸ”— Credly Badge
2025 GIAC Advisory Board Member SANS Institute πŸ”— Credly Badge

Research Areas & Expertise

Security & Identity:
Identity Assurance β€’ Digital Identities β€’ Digital Signatures β€’ Web of Trust β€’ NIST SP 800-63A β€’ Single Sign-On (SSO/SAML) β€’ Applied Cryptography β€’ Web Application Security

Cloud & DevOps:
Cloud Security Automation β€’ DevSecOps β€’ CI/CD β€’ Infrastructure as Code β€’ High Availability Architecture β€’ Software Supply Chain Security

Development & Integration:
Software Development Lifecycle β€’ Systems Integrations (SIS, Salesforce, Canvas, Twilio) β€’ Data Architecture β€’ Project Management

Training History

2024

  • SEC540: Cloud Security and DevSecOps Automationβ„’ - SANS Institute
    Course Details

2022

  • Delegation Skills for Busy Leaders ("Why & How")
    Read Article

2021

2020

  • Supervision: Core Competencies: Meeting the Needs of Today's Employees - Employers Council
  • Team Leadership: Leading Teams - Employers Council
  • Coaching Essentials: Partnering for Performance - Employers Council
  • Conflict: Self-Management - Employers Council

2019

2014

  • Building an End-to-End Web Application with ASP.NET MVC5 (C#), EF Code First, HTML5 and jQuery - Interface Technical Training
    Course Details
  • SEC542: Web App Penetration Testing and Ethical Hackingβ„’ - SANS Institute
    Course Details

Technical Skills

Database & Data Management

Proficiency: β˜…β˜…β˜…β˜…β˜†
Microsoft SQL Server β€’ MySQL β€’ Oracle β€’ Couchbase

Software Development

Proficiency: β˜…β˜…β˜…β˜…β˜…
C# β€’ ASP.NET MVC β€’ Entity Framework (Code First) β€’ Classic ASP with custom COM objects β€’ Node.js β€’ PHP β€’ CodeIgniter β€’ Laravel

UI/UX Development

Proficiency: β˜…β˜…β˜…β˜…β˜†
XHTML β€’ CSS β€’ JavaScript β€’ Bootstrap β€’ jQuery

HTTP & Web Standards

Proficiency: β˜…β˜…β˜…β˜…β˜…
Cross-Origin Resource Sharing (CORS) β€’ Sub-Resource Integrity (SRI) β€’ Content Security Policy (CSP) β€’ SSL Configuration β€’ HTTP Strict Transport Security (HSTS) β€’ Proxy Configuration β€’ REST APIs β€’ Request Tracing

Web Application Security

Proficiency: β˜…β˜…β˜…β˜…β˜…
OWASP Top 10 β€’ SANS SWAT Checklist β€’ Manual Penetration Testing β€’ Applied Cryptography β€’ Systems Analysis β€’ Network Mapping

Applied Cryptography

Proficiency: β˜…β˜…β˜…β˜…β˜†
Key Derivation Functions β€’ Salts & Initialization Vectors β€’ Message Authentication Codes β€’ Hashing Algorithms β€’ Key Management β€’ Best Practices Implementation

Infrastructure & DevOps

Proficiency: β˜…β˜…β˜…β˜…β˜…
TCP/UDP Load Balancing β€’ High Availability (HAProxy, NGINX) β€’ Web Server Configuration (IIS, Tomcat) β€’ DNS Management β€’ Firewall Management β€’ Virtual IP Management β€’ SSL Termination β€’ Clustering β€’ Automation (Puppet)

CI/CD & Version Control

Proficiency: β˜…β˜…β˜…β˜…β˜…
Git β€’ Environment Branches β€’ Pull Requests β€’ Branch Policies β€’ Pre-Deployment Approval β€’ Continuous Delivery β€’ Bitbucket β€’ GitHub β€’ Azure DevOps

Leadership & Management

Proficiency: β˜…β˜…β˜…β˜…β˜…
Technical Leadership: Mentoring β€’ Architecture Decisions β€’ Standard Operating Procedures β€’ Compliance Review β€’ Security Review β€’ Best Practices β€’ Release Coordination

Project Management: Requirements Gathering β€’ Cost Evaluation β€’ Systems Analysis β€’ Expectation Management β€’ Work Coordination & Direction

Professional Experience

Manager, Web Services

Mar 2021 - Present

  • Instituted Standard Operating Procedures for team operations
  • Implemented Continuous Integration and Continuous Delivery for .NET applications, libraries, and application environments using Azure Pipelines
  • Developed business-aligned progression plans and job descriptions for .NET web application developers through Senior level
  • Created and implemented Team Charter

Supervisor, Web Services

Nov 2019 - Mar 2021

  • Instituted Change Management, Project Management, and Software Development Life Cycle processes
  • Conducted employee training, mentoring, and supervision
  • Led initial formation of core development team
  • Served as Interview panel member and Subject Matter Expert (SME)

Developer, Web Applications

Sep 2013 - Nov 2019

  • Developed and deployed infrastructure management as code using Puppet Enterprise
  • Configured and deployed Single Sign-On identity provider services and connectors (CAS, SAML, OAuth)
  • Led research and migration of on-premise application clusters to new high availability environment (HAProxy)
  • Spearheaded research and migration of legacy web applications (Classic ASP) to modern technology stack (ASP.NET MVC, C#)
  • Managed in-house planning, development, and maintenance of College Portal, Website, internal business applications, community applications, and third-party service integrations

Adjunct Faculty (Part-Time), Computer Systems & Applications

Fall 2016

  • Taught ASP.NET 4 using "Sam's Teach Yourself ASP.NET 4 in 24 Hours" (ISBN: 978-0672333057) augmented with industry-relevant curriculum

Adjunct Faculty (Part-Time), Computer Systems & Applications

Fall 2015

  • Taught ASP.NET using "Beginning ASP.NET in C# and VB" (ISBN: 978-1118846773) augmented with industry-relevant curriculum

Lead Developer, Web Applications

Jun 2011 - Sep 2013

  • Developed custom web applications using LAMP stack
  • Developed and supported integrations with ad exchange, marketing automation, content management, publishing, event and newsletter management, payment processing, and customer relationship management
  • Managed Linux servers, cloud services, and web application firewall
  • Provided remote desktop support

Web Design Teacher, Career & Technical Education

Aug 2008 - Aug 2010

  • Taught Business Math, Web Design and Development, and Career Preparation
  • Advised Future Business Leaders of America (FBLA) student organization

Technology Specialist

2004, 2005 - 2008

  • Managed account provisioning in Active Directory
  • Led district website development and server rebuild
  • Managed security, networking, and content filtering
  • Administered email management and spam filtering
  • Provided desktop and printer support, imaging, and inventory management

Notable Achievements & Projects

2020

SAML 2.0 Identity Provider Deployment
Assisted local city IT director in successfully deploying their first SAML 2.0 Identity Provider

2019

Contract Recovery & In-House Execution
Recouped service fees (FFP) in excess of $40,000 from vendor breach of website build project contract and executed full project requirements in-house using Cascade CMS

College Portal Modernization
Launched new, mobile-friendly College Portal rebuilt in-house using ASP.NET MVC (C#), yielding 95% improvement to login times and application performance

2018

Change Management Innovation
Replaced CAS Service Management WebApp with custom Change Management solution using Azure Repos and Azure Pipelines

2017

Office 365 SSO Integration
Successfully configured and deployed delegated Single Sign-On authentication for Office 365 applications orchestrating onload.js with first successful in-house ADFS Claims Provider supporting SAML 2.0

First SAML 2.0 Identity Provider
Successfully configured and deployed first SAML 2.0 Identity Provider

SDLC & Release Management Adoption
First adoption of a Software Development Life Cycle process governed by Release Management using A successful Git branching model by Vincent Driessen, Developing and Deploying with Branches and Deployments Best Practices by Beanstalk Guides

Project Management Framework
First adoption of Project Management using Azure DevOps for Project Managers by Cals Tutorials

2016

Cryptographic Implementation
Self-taught implementation of FIPS-197 in Arduino C

Hack the Pentagon Recognition
Challenge Coin received from Department of Defense for submitting valid findings during Federal Government's first ever bug bounty program, Hack the Pentagon hosted by HackerOne

2013

Open Source Contribution
Contributed software patch accepted by Single Sign-On software provider, Jasig/Apereo CAS, resolving lack of cluster support in cryptographic operations via CAS-1386

2005

Desktop Management Automation
Orchestration of computer lab imaging, inventory management, and post-installation tasks using Altiris, DeepFreeze, Windows PE, and AutoIt

Mac OS 9 Imaging Automation
Automated arrangement of desktop icons on Mac OS 9 during annual imaging using AppleScript

2004

Active Directory Automation
Automated import of 1k+ student accounts from Student Information System into Active Directory using Visual Basic script

PGP

Statement

The following PGP fingerprints belong to the owner of this repository: Matt Borja.

Fingerprint Created Status
0398 B8E1 0560 7E7B A675 7ACF C891 9DBC B39E 6F72 2024-10-07 Active (Latest). Certified with non-revocable signatures by: A1C7E813F160A407, 33688C2EDC08CD38, 9DB9CDDC77088F26
99BB 608E 3038 0C45 1952 D6BB A1C7 E813 F160 A407 2024-10-07 Active (Current). Certified by: 33688C2EDC08CD38
F30F F4FC 9365 8457 4EE3 2518 3368 8C2E DC08 CD38 2021-12-29 Superseded
6FDD 7A12 197C 04F8 F510 585C 9DB9 CDDC 7708 8F26 2022-04-18 Expired
3371 63B2 51AD 534D 6E30 8DC4 BC60 808C E2A8 20F6 2022-04-18 Revoked
4105 C4E5 774F 401B 1824 6910 FED8 1E8C 4D67 3B96 2022-04-18 Revoked
8ED0 E383 176C FAE7 8899 0F29 22E7 1A76 0A44 E2D6 2012-03-07 Revoked
F88A 7363 03AB F22B 60F4 A9C1 C892 093A 3570 183E 2003-08-28 Revoked

Asserted by cryptographically signed commit: be02acb@master (learn more).

Pinned Loading

  1. saas-mvp saas-mvp Public template

    Forked from aws-samples/aws-serverless-saas-workshop

    Python 1