Bob Aman

Staff AI Security Engineer at Discord

Minneapolis, Minnesota, United States
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts

Summary

🤩
Rockstar
🎓
Top School
Bob Aman is a Staff Product Security Engineer with 18 years of experience building secure, production-grade systems across startups and major tech companies. He blends hands-on backend and DevOps expertise—demonstrated by contributions to projects like BuzzFeed's SSO and Google’s Signet OAuth library—with leadership roles at Slack, Remitly, and now Discord. As a founder of a security consultancy and former Principal/Sr Staff engineer, he focuses on automated security decisioning, threat-informed product design, and mentoring engineering teams. His early career in developer programs and diverse stack experience (Ruby, Go, Node, Docker) give him a rare mix of developer empathy and security rigor. Notably, he’s improved deployment workflows and proxy/TLS behaviors in open-source SSO tooling, showing attention to both security and operational ergonomics. Based in Minneapolis, he combines product-focused security strategy with pragmatic engineering to make secure systems easier to build and operate.
code19 years of coding experience
job20 years of employment as a software developer
bookBS, Computer Science, BS, Computer Science at Rochester Institute of Technology
bookWebster Schroeder HS
languagesEnglish
stackoverflow-logo

Stackoverflow

Stats
33,029reputation
2.9mreached
261answers
21questions
Badges
sinatra
top-5%
git
top-5%
regex
top-5%
redirect
top-1%
oauth
top-1%
orm
top-5%
github-logo-circle

Github Skills (49)

architecture10
http10
user-authentication10
authentication10
security10
ruby10
uuid10
go10
rest10
devops10
oauth10
redirect10
google-api9
punycode9
git9

Programming languages (19)

C#JavaC++RustCMakefileGoHTML

Github contributions (5)

github-logo-circle
sporkmonger/addressable

Sep 2007 - Jul 2022

Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. It is flexible, offers heuristic parsing, and additionally provides extensive support for IRIs and URI templates.
Role in this project:
userBack-end Developer
Contributions:17 reviews, 592 commits, 123 PRs in 15 years 1 month
Contributions summary:Bob contributed to the Addressable library by implementing features related to URI templates and normalization. The user's contributions included updates to support URI Template variable extraction and the addition of a pure Ruby IDNA implementation to handle international domain names. They also fixed bugs related to URL joining and made code style improvements, with various documentation updates.
parsingrubyuri-templateuri
googleapis/signet

Oct 2010 - Jun 2014

Signet is an OAuth 1.0 / OAuth 2.0 implementation.
Role in this project:
userBack-end Developer
Contributions:37 commits, 7 comments, 2 issues in 3 years 8 months
Contributions summary:Bob primarily focused on maintaining and improving the Signet library, an OAuth implementation. The commits reveal work on core functionality, including the implementation of OAuth 1.0 and 2.0 client functionalities, and the addition of options. Additionally, there's evidence of updating the version and changelog file. The commits also include addressing a bug fix related to authorization URI.
oauth
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.
Request Free Trial