# Bob Heineman

**Security Platform Engineer | Cloud Security Automation | Repeatable Tooling**

Sugar Grove, Illinois  
heineman.bob@gmail.com  
[linkedin.com/in/bob-heineman-555b4329](https://www.linkedin.com/in/bob-heineman-555b4329)

## Professional Summary

Security platform and cloud infrastructure engineer with 15+ years of
experience building production software, distributed systems, cloud platforms,
delivery automation, and security engineering capabilities. Turns fragmented
security requirements and cloud data into durable governance, enrichment,
ownership, reporting, and remediation systems. Combines hands-on depth in
Python, Terraform, AWS, GCP, Kubernetes, and CI/CD with technical leadership,
developer enablement, and repeatable engineering tooling.

## Selected Impact

* Led the progression from enterprise cloud-security platform rollout to the
  enrichment, governance, ownership, routing, and reporting systems required to
  make security data operational.

* Avoided $800,000 in vendor fees across four years ($200,000 per year) with a multi-property
  employee-survey and reporting platform delivered initially in approximately
  two weeks.

* Reduced observability operating cost by $48,000 per year while
  improving deployment traceability and production support.

* Led a company-wide move from Vagrant to Kubernetes-based local development,
  saving each of 35 developers 45 minutes per day and recovering 26.25
  engineering hours daily. That is
  roughly 3.3 FTEs, or an estimated $560,000 in annual engineering capacity,
  while removing the need for high-performance desktop hardware.

## AI Workflow Engineering

* Integrate Codex, Claude, ChatGPT, Gemini, and Antigravity into daily
  development through editor extensions and command-line workflows for
  implementation, debugging, review, test design, documentation, and technical
  analysis.

* Build custom agents for repeatable engineering tasks using Codex and Gemini
  Pro, combining repository context, durable instructions, validation steps,
  and human approval boundaries.

* Use connected AI workflows to organize Jira-driven development: gather ticket
  context, structure implementation work, maintain alignment between code and
  acceptance criteria, summarize progress, and surface blockers or follow-up
  actions.

* Apply AI to evidence collection, status reporting, documentation maintenance,
  and cross-source synthesis while retaining human review for technical
  decisions and production changes.

## Core Expertise

Security Platform Engineering | Cloud Security | Security-as-Code | DevSecOps |
Infrastructure as Code | Distributed Systems | Backend Engineering | Security
Automation | Governance and Ownership Mapping | Reporting Platforms | AI Agent
Workflows | Developer Tooling | Technical Leadership

## Professional Experience

### Senior Software Security Engineer | Wonder / Grubhub

**August 2025-Present**

* Designed a cohesive service registry spanning Wonder's multi-brand,
  multi-cloud environment, connecting technical assets, services,
  organizational structures, and accountable owners.

* Built a dynamic entity-resolution layer using authoritative data, resource
  tags, naming rules, structural evidence, and weighted similarity strategies
  to identify service ownership.

* Created a tiered confidence model that accepts high-trust mappings
  automatically, surfaces ambiguous candidates for review, and exposes missing
  ownership data as actionable gaps.

* Evaluated 1,455 services in a representative automation run, classifying
  1,222, identifying 233 gaps, and synchronizing 13 downstream projects.

* Connected cloud findings with services, owners, stakeholders, and remediation
  workflows, replacing fragmented handling with measurable SLAs and a
  consistent cross-team operating cadence.

* Replaced one-off security reporting with reusable workflows that translate
  technical posture data into service-aware and ownership-aware outputs for
  operators and leaders.

* Oversee cloud-security finding SLAs and work across the organization to
  clarify accountability, surface blockers, and keep remediation visible and
  moving.

* Improve production hardening through least-privilege access, secret
  management, observability, safer input handling, modular infrastructure, and
  resilient execution.

* Apply custom AI agents and Jira-connected workflows to accelerate
  implementation, organize ticket-driven delivery, generate progress summaries,
  maintain documentation, and preserve traceable human review.

### Senior Software Engineer | Fetch

**November 2021-May 2025**

* Refactored tightly coupled e-receipt infrastructure into independently
  deployable components with safer release workflows and clearer production
  ownership.

* Built controlled rollout and rollback capabilities, reusable deployment
  annotations, and traceability that improved release safety and production
  investigation.

* Created self-service operational tooling that allowed internal users to
  manage routine configuration without depending on an engineer for every
  change.

* Migrated observability platforms, reducing ongoing operating cost by $48,000
  per year.

* Automated lifecycle and cleanup workflows across Kafka, Lambda, EventBridge,
  DynamoDB, and Redis systems, reducing manual work and operating overhead.

### Independent Consultant | Olcott Plastics and Rush Street Gaming

**2019-2021**

* Improved Java delivery at Olcott Plastics through Jenkins automation,
  containerized workflows, automated documentation, and streamlined continuous
  deployment.

* Reviewed AWS infrastructure for Rush Street Gaming and automated idle-resource
  identification and cleanup using Python and boto3.

* Improved security-event alerting and enhanced internal Python and Flask
  applications.

### Lead Backend Engineer | physIQ

**July 2018-July 2019**

* Designed and delivered scalable Python APIs within an FDA-regulated
  engineering environment.

* Standardized testing practices and introduced GCP Stackdriver monitoring,
  increasing observability and reducing production issues.

* Led a company-wide shift from Vagrant to Kubernetes-based local development,
  saving each of 35 developers 45 minutes per day and recovering 26.25
  engineering hours daily - roughly 3.3 FTEs or an estimated $560,000 in annual
  engineering capacity - while
  eliminating high-performance desktop requirements.

* Enabled local services to connect with external GCP infrastructure, creating a
  more efficient hybrid development workflow.

### Lead Software Engineer / Software Engineer | Rush Street Gaming

**September 2014-July 2018**

* Led engineering practices, code reviews, design sessions, stakeholder
  communication, and vendor relationships while establishing reusable
  foundations for future engineers.

* Built custom ETL pipelines that satisfied regulatory Ingress Block
  requirements and delivered historical time-series gaming data to centralized
  data lakes and Snowflake clusters, enabling data scientists to analyze gaming
  trends.

* Architected AWS-based solutions for land-based casino operations and delivered
  business-critical applications within gaming-board regulatory constraints.

* Maintained jurisdiction-required gaming licenses for onsite access to
  regulated casino data and systems, traveling to properties for technical
  consultation, server management, and production support.

* Developed a full-stack application for casino properties to manage slot-floor
  layouts, game assignments, and enriched machine metadata, automating
  regulatory reporting and saving 30 employees 2.5 hours each per week - 75
  staff-hours weekly and approximately 3,900 annually.

* Built a Java integration and workflow layer over Konami casino-management
  APIs, streamlining player-account and reward-redemption tasks while surfacing
  real-time guest profiles and activity trends through a simpler interface.
  Reduced guest wait times, improved service visibility, and shortened training
  for new property staff.

* Deployed Docker infrastructure across property environments and the company
  VPC and established CI/CD using Bitbucket, Jenkins, AWS, and custom
  automation.

* Avoided $800,000 in vendor fees across four years ($200,000 per year) with a multi-tenant
  employee-survey platform serving four casino properties.

* Designed a one-time-code model that protected employee anonymity while
  preserving useful organizational reporting and supported the system through
  repeated annual survey cycles.

### Software Development Engineer, Prime | Amazon

**January 2013-August 2014**

* Built and operated customer-facing Prime signup services across retail,
  Kindle e-readers, Kindle Fire, Fire Phone, and Fire TV.

* Managed multiple Prime endpoints with exceptionally high request volume,
  requiring disciplined capacity planning, instrumentation, and operational
  readiness.

* Prepared Prime front-page entry points for holiday peaks by analyzing
  prior-year AWS traffic trends and building service-specific dashboards for
  critical hot paths.

* Operated a focused set of AWS services deployed across thousands of servers,
  using metrics and dependency analysis to identify capacity, latency, and
  availability risk.

* Managed Prime promotional content through release-flagging and scheduling
  systems, enabling coordinated, reversible launches across customer entry
  points.

* Developed and tested Prime signup for an unreleased Kindle device inside a
  restricted-access downtown Seattle facility, working from a windowless
  secure room.

* Passed designs through rigorous review and delivered disciplined sprints with
  technical program managers, product representatives, engineering managers,
  and engineers.

* Contributed to the company-wide Prime price-change launch and supported Prime
  Instant Video launches in Germany and the United Kingdom.

* Created a more efficient device-development process that saved each team
  member an average of approximately three hours per day.

* Developed APIs, service integrations, rule-driven content, internal tooling,
  metrics, alarms, and operational dashboards.

* Participated in weekly pager rotations and organized a technical brownbag
  series that reduced dependence on tribal knowledge.

### Earlier Experience

**Software Developer | Passport Health Communications | 2012**

Migrated claims-processing logic to a new government healthcare-transaction
standard; built a configurable service that automated claims batching and
submission; and created operator monitoring and alarming for production
file-transfer workflows.

**Consultant / Senior Consultant | Sogeti | 2011-2012**

Built enterprise web applications, services, call-center intake pipelines, and
government-compliant workflows. Led client requirements and demonstrations,
organized internal .NET training, and mentored junior consultants.

**Global Information Systems Intern | Abbott | 2009-2010**

Automated server configuration and application deployment across more than 300
enterprise servers, along with data normalization, database maintenance, and
ETL support using Python, Jython, Unix scripting, C++, and infrastructure
tooling.

## Technical Skills

**Languages:** Python, Java, Go, Ruby, JavaScript, C#

**Cloud and Infrastructure:** AWS, GCP, Azure, Terraform, Kubernetes, Helm,
Docker, serverless architectures

**Security:** Cloud security posture management, cloud governance, IAM, secrets
management, application security, security automation, security-as-code

**AI Workflow Tooling:** Codex, Claude, ChatGPT, Gemini, Gemini Pro,
Antigravity, custom agents, editor extensions, CLI workflows, Jira-connected
delivery, progress synthesis

**Data and Integration:** PostgreSQL, MySQL, Oracle, Microsoft SQL Server,
Snowflake, Amazon Redshift, Redis, Kafka, SQS, SNS, EventBridge

**Delivery and Operations:** GitHub Actions, Jenkins, CircleCI, Bitbucket
Pipelines, Grafana, monitoring, tracing, CI/CD

**Engineering:** Distributed systems, REST APIs, event-driven architecture,
service catalogs, ownership mapping, reporting platforms, developer tooling,
technical mentorship

## Education

**Bachelor of Science, Computer Science**  
Northern Illinois University
