Resume
Kathleen Goeschel, Ph.D.
Profile
Security leader and applied AI practitioner with 25+ years in technology spanning software engineering, application security architecture, and AI/ML research. Currently focusing on AI security and Agentic strategy for Red Hat's Product Security organization. PhD research applied machine learning to improve static code analysis — the intersection of AI and security has been the throughline of my career. Published IEEE researcher, Red Hat Summit speaker, and acknowledged contributor to the OpenSSF Software Security Mobilization Plan presented to The White House.
Experience
Principal Product Security Engineer — AI Specialist
Aug 2025 – PresentRed Hat, Inc. · Remote
- Define and drive AI security standards, threat models, and risk assessments for AI/ML-integrated products across Red Hat's portfolio
- Partner with engineering, product, and leadership to embed AI security practices into the SDLC
- Propose and design security tooling and automation leveraging LLMs to improve vulnerability detection and developer workflows
- Advise cross-organizational teams on secure AI development and deployment practices
- Participate in the CoSAI Community (WS3 & WS4) to share back learnings with the community while monitoring for industry wide novel and best practices we can implement.
General Manager
Jan 2025 – Aug 2025The Outpost BBI · Bois Blanc Island, MI
- Co-founded and managed the sole restaurant, bar, and general store on a remote island in Northern Michigan
- Stood up complete business operations: POS systems, payroll, accounting, vendor management, supply chain logistics, inventory, and compliance
- Achieved 30% year-over-year revenue growth while cutting expenses through cost-control measures
- Hired, trained, and managed a cross-functional team in a high-constraint environment
Principal Portfolio Architect — Product Security
Jun 2021 – Nov 2024Red Hat, Inc. · Remote
- Established supply chain security roadmaps, OKRs, and KPIs with senior leadership; drove corporate strategy across teams
- Owned and delivered critical supply chain programs: SAST/SCA scanning, code signing, event logging, identity management, automated compliance evidence generation
- Architected projects and led engineers across multiple departments and engineering teams
- Contributed to OpenSSF working groups (Secure Tooling, Supply Chain Integrity, SLSA, SIG SBOM); served as Red Hat's ambassador to the OpenSSF
- Led restructuring of the supply chain team — defined processes, roles, and responsibilities
- Selected for Red Hat's Executive Leadership Accelerator (ELA) program, 2024
- Recognized as IBM Top Technical Talent, 2023
- Promoted from Senior Product Security Engineer (2021–2023)
Security Research & Architecture — AppSec
Jun 2017 – May 2020Ultimate Software · Remote
- Architected and directed the enterprise SAST/SCA code scanning program end-to-end
- Designed and built the automated application security scanning pipeline
- Advised hundreds of developers across multiple teams and tech stacks on product security vulnerabilities and secure coding practices
- Served as representative point of contact for SOC2 auditing of the application security program
- Researched, authored, and implemented security policies, procedures, and secure coding standards
Senior Software Developer — Team Lead
Nov 2010 – Nov 2015Chico's FAS · Fort Myers, FL
- Led a development team: daily scrum, sprint planning, task assignment, velocity tracking, and cross-departmental coordination
- Standardized the SDLC — introduced peer code reviews, QA processes, approval documentation, and separation of duties
- Developed high-traffic, interactive retail websites and mobile applications
- Progressed from Associate Software Developer (contractor) to Senior Developer & Team Lead
Director of Software Development
Aug 2007 – Nov 2009Emergence · Fort Myers, FL
- Led engineering for a startup building a SaaS electronic medical records (EMR) application
- Directed and grew the software development team; architected the application and APIs
- Built integrations with third-party systems using HL7, X12, and XML
- Ensured HIPAA compliance through evolving regulatory requirements
Earlier Career
Web applications, corporate intranet, and event management systems. Dual role as sysadmin.
Digital telecommunications systems from POTS to OC-192. Cisco, Lucent, and Alcatel equipment. CWA Union Steward.
Progressed from administrative assistant to stock cashier. Earned Series 7 license on own initiative.
Full-stack websites and mobile applications for individuals and small businesses.
Education
Ph.D. in Information Assurance
Nova Southeastern University · 2019
Dissertation: Feature Set Selection for Improved Classification of Static Analysis Alerts
M.S. in Information Security
Nova Southeastern University · 2016
B.S. in Information Technology (Software Development)
Barry University · 2006
A.A. in Psychology
Miami Dade College · 1997
Publications
Speaking Engagements
Community & Volunteering
Certifications & Recognition
- Executive Leadership Accelerator (ELA), Red Hat — 2024
- IBM Top Technical Talent — 2023
- ISC2 Certified Secure Software Lifecycle Professional (CSSLP) — 2015–Present
- Excellence Award, Chico's FAS — 2015
- Series 7 License (FINRA) — 1998