Resume

Kathleen Goeschel, Ph.D.

Profile

Security leader and applied AI practitioner with 25+ years in technology spanning software engineering, application security architecture, and AI/ML research. Currently focusing on AI security and Agentic strategy for Red Hat's Product Security organization. PhD research applied machine learning to improve static code analysis — the intersection of AI and security has been the throughline of my career. Published IEEE researcher, Red Hat Summit speaker, and acknowledged contributor to the OpenSSF Software Security Mobilization Plan presented to The White House.

Experience

Principal Product Security Engineer — AI Specialist

Aug 2025 – Present

Red Hat, Inc. · Remote

  • Define and drive AI security standards, threat models, and risk assessments for AI/ML-integrated products across Red Hat's portfolio
  • Partner with engineering, product, and leadership to embed AI security practices into the SDLC
  • Propose and design security tooling and automation leveraging LLMs to improve vulnerability detection and developer workflows
  • Advise cross-organizational teams on secure AI development and deployment practices
  • Participate in the CoSAI Community (WS3 & WS4) to share back learnings with the community while monitoring for industry wide novel and best practices we can implement.

General Manager

Jan 2025 – Aug 2025

The Outpost BBI · Bois Blanc Island, MI

  • Co-founded and managed the sole restaurant, bar, and general store on a remote island in Northern Michigan
  • Stood up complete business operations: POS systems, payroll, accounting, vendor management, supply chain logistics, inventory, and compliance
  • Achieved 30% year-over-year revenue growth while cutting expenses through cost-control measures
  • Hired, trained, and managed a cross-functional team in a high-constraint environment

Principal Portfolio Architect — Product Security

Jun 2021 – Nov 2024

Red Hat, Inc. · Remote

  • Established supply chain security roadmaps, OKRs, and KPIs with senior leadership; drove corporate strategy across teams
  • Owned and delivered critical supply chain programs: SAST/SCA scanning, code signing, event logging, identity management, automated compliance evidence generation
  • Architected projects and led engineers across multiple departments and engineering teams
  • Contributed to OpenSSF working groups (Secure Tooling, Supply Chain Integrity, SLSA, SIG SBOM); served as Red Hat's ambassador to the OpenSSF
  • Led restructuring of the supply chain team — defined processes, roles, and responsibilities
  • Selected for Red Hat's Executive Leadership Accelerator (ELA) program, 2024
  • Recognized as IBM Top Technical Talent, 2023
  • Promoted from Senior Product Security Engineer (2021–2023)

Security Research & Architecture — AppSec

Jun 2017 – May 2020

Ultimate Software · Remote

  • Architected and directed the enterprise SAST/SCA code scanning program end-to-end
  • Designed and built the automated application security scanning pipeline
  • Advised hundreds of developers across multiple teams and tech stacks on product security vulnerabilities and secure coding practices
  • Served as representative point of contact for SOC2 auditing of the application security program
  • Researched, authored, and implemented security policies, procedures, and secure coding standards

Senior Software Developer — Team Lead

Nov 2010 – Nov 2015

Chico's FAS · Fort Myers, FL

  • Led a development team: daily scrum, sprint planning, task assignment, velocity tracking, and cross-departmental coordination
  • Standardized the SDLC — introduced peer code reviews, QA processes, approval documentation, and separation of duties
  • Developed high-traffic, interactive retail websites and mobile applications
  • Progressed from Associate Software Developer (contractor) to Senior Developer & Team Lead

Director of Software Development

Aug 2007 – Nov 2009

Emergence · Fort Myers, FL

  • Led engineering for a startup building a SaaS electronic medical records (EMR) application
  • Directed and grew the software development team; architected the application and APIs
  • Built integrations with third-party systems using HL7, X12, and XML
  • Ensured HIPAA compliance through evolving regulatory requirements

Earlier Career

Programmer & System Administrator · Kozyak, Tropin & Throckmorton · 2005–2007

Web applications, corporate intranet, and event management systems. Dual role as sysadmin.

Electronic Technician · BellSouth · 2000–2005

Digital telecommunications systems from POTS to OC-192. Cisco, Lucent, and Alcatel equipment. CWA Union Steward.

Operations & Compliance · Morgan Stanley · 1997–2000

Progressed from administrative assistant to stock cashier. Earned Series 7 license on own initiative.

Freelance Web Designer · 2004–2010

Full-stack websites and mobile applications for individuals and small businesses.

Education

Ph.D. in Information Assurance

Nova Southeastern University · 2019

Dissertation: Feature Set Selection for Improved Classification of Static Analysis Alerts

M.S. in Information Security

Nova Southeastern University · 2016

B.S. in Information Technology (Software Development)

Barry University · 2006

A.A. in Psychology

Miami Dade College · 1997

Publications

2025 "DACSA: Data Authorization Controls for Securing Agentic AI Systems"
2024 "Open Source Isn't Itself Insecure — But Your Supply Chain Could Be" — LinkedIn
2022 "Software Supply Chain Security Assurance at Red Hat: A Partnership Process Model" — Red Hat Customer Portal
2019 "Feature Set Selection for Improved Classification of Static Analysis Alerts" — Doctoral Dissertation, Nova Southeastern University
2016 "Reducing False Positives in Intrusion Detection Systems Using Data-Mining Techniques" — IEEE SoutheastCon 2016

Speaking Engagements

Red Hat Summit 2022 "Software Supply Chain: Risks, Threats, and What You Can Do"
Ultimate Software WIT 2019 "Application Security Basics"
Ultimate Software DevCon 2019 "Application Security and the OWASP Top Ten"
Ultimate Software ISCon 2018 "Open Source Software Scanning Technologies"

Community & Volunteering

Founder Crescendo Alliance — 501(c)(3) nonprofit breaking down financial barriers in classical music. Built the companion technology platform with Claude.
Acknowledged Contributor OpenSSF / Linux Foundation — "The Open Source Software Security Mobilization Plan" presented to The White House (2022)
Contributor CoSAI, OpenSSF / Linux Foundation
Board Member Bois Blanc Island Parks & Recreation (2025–Present)
Board Member & Secretary Gulf Coast Symphony, Fort Myers, FL (2021–2023) — largest community orchestra in the U.S.
Community Leader WIT (Women in Technology) Network, Florida Chapter (2021–2022)

Certifications & Recognition

  • Executive Leadership Accelerator (ELA), Red Hat — 2024
  • IBM Top Technical Talent — 2023
  • ISC2 Certified Secure Software Lifecycle Professional (CSSLP) — 2015–Present
  • Excellence Award, Chico's FAS — 2015
  • Series 7 License (FINRA) — 1998

Technical Strengths

Security

AppSec (SAST/SCA)Supply Chain SecuritySLSASBOMSigstoreThreat ModelingSecure SDLCVulnerability ManagementCode SigningSOC2NISTOWASPDevSecOps

AI / ML

ML for SecuritySVMDecision TreesNaive BayesLSTMLLM SecurityPrompt InjectionData PoisoningModel IntegrityAI-Augmented Tooling

Engineering

PythonJavaJavaScriptGoPHPSQLC++Node.jsREST/SOAP APIsMicroservicesKubernetesDockerAWS/GCPGit

Leadership

Team BuildingMentorshipProduct OwnershipOKRs/KPIsCross-Org CollaborationVendor ManagementGovernance