Bozeman, Montana, United States
2K followers 500+ connections

Join to view profile

About

I lead enterprise cybersecurity for The Washington Post and Arc XP, including cyber risk…

Articles by Jason

  • How to Achieve Your Goals

    In order to achieve your goals, you need to stop focusing so hard on the solution. Counter-intuitive, right? Let me…

    1 Comment
  • How to Be an Effective Manager

    I’ve found that there are four distinct styles of management: Directing, Supporting, Coaching, and Delegating. Each can…

    1 Comment
  • How to Be an Effective Leader

    I’ve spent the last 20 years leading teams of software developers, testers, and ethical hackers on a wide variety of…

Activity

2K followers

See all activities

Experience & Education

  • The Washington Post

View Jason’s full experience

By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.

Licenses & Certifications

Publications

  • Web Architecture Pocket Guide

    Microsoft

    The Web Architecture Pocket Guide provides an overview and prescriptive guidance for designing Web applications on the .NET platform.

    See publication
  • Mobile Architecture Pocket Guide

    Microsoft

    The Mobile Architecture Pocket Guide provides an overview and prescriptive guidance for designing mobile applications on the .NET platform. Updated to incorporate community feedback.

    See publication
  • Improving Web Services Security: Scenarios and Implementation Guidance for WCF

    Microsoft

    This guide shows you how to make the most of Microsoft® Windows Communication Foundation (WCF). WCF is Microsoft's solution for developing applications based on a service-oriented architecture (SOA) methodology. The guide contains proven practices, end-to-end applications scenarios, guidelines, a Q&A, and task-based “how-to” articles.

    See publication
  • Service Architecture Pocket Guide

    Microsoft

    The Service Architecture Pocket Guide provides an overview and prescriptive guidance for designing services on the .NET platform.

    See publication
  • Application Architecture Guide 2.0

    Microsoft

    This guide provides design-level guidance for the architecture and design of applications built on the .NET Framework. It focuses on the most common types of applications, partitioning application functionality into layers, components, and services, and walks through their key design characteristics. This guide is a collaborative effort between patterns & practices, product teams, and industry experts.

    See publication
  • Team Development with Visual Studio Team Foundation Server

    Microsoft

    This guide shows you how to make the most of Team Foundation Server. It starts with the end in mind, but shows you how to incrementally adopt TFS for your organization. It's a collaborative effort between patterns & practices, Team System team members, and industry experts.

    See publication
  • Regulatory Compliance Demystified

    Microsoft

    For a developer, understanding the issues around regulatory compliance can be a difficult and frustrating endeavor. This article makes sense of regulatory compliance from a developer's point of view. It examines Sarbanes-Oxley, HIPAA, and other regulations, and covers the most important best practices that are common across multiple pieces of legislation.

    See publication
  • How to Perform a Security Code Review

    Microsoft

    A properly conducted code review can do more for the security of your code than nearly any other activity. A code review allows you to find and fix a large number of security issues before the code is tested or shipped. In addition, the code review process allows the development team to share security best practices and experience, which can prevent future security issues.

    See publication
  • Security Engineering Explained

    Microsoft

    To meet your application security objectives, you must integrate security into your application development life cycle. You can do so by including specific security-related activities in your current software engineering processes. These activities include identifying security objectives, applying secure design guidelines, patterns, and principles, creating threat models, conducting architecture and design reviews for security, performing regular code reviews for security, testing for security,…

    To meet your application security objectives, you must integrate security into your application development life cycle. You can do so by including specific security-related activities in your current software engineering processes. These activities include identifying security objectives, applying secure design guidelines, patterns, and principles, creating threat models, conducting architecture and design reviews for security, performing regular code reviews for security, testing for security, and conducting deployment reviews to ensure secure configuration.

    See publication
  • Application Security By Design: Security as a Complete Lifecycle Activity

    Security Innovation

    Secure software is a software development problem. Its solution is the responsibility of every member of the software development team –from managers and support staff to developers, testers and IT staff. Security must be on everyone’s mind throughout every phase of the software lifecycle. This paper describes complete lifecycle activities aimed at producing more secure and robust code that can better withstand attack.

    See publication
Join now to see all publications

Patents

  • Automated system that tests software on multiple computers

    Issued US 7,437,713

    An automation system to test software products on multiple computers dynamically, enabling the automation system to reconfigure or repurpose all or some systems to optimize the pairing of test with systems that will return test results in the minimum amount of time.

    Other inventors
    See patent

Projects

  • Holodeck

    -

    Holodeck is a unique test tool that uses fault injection to simulate real-world application and system errors for Windows applications and services - allowing testers to work in a controlled, repeatable environment to analyze and debug error-handling code. Holodeck is the first commercial fault-simulation tool and was developed by leading researchers in the application quality field. It is used by organizations like Microsoft, Adobe, EMC and McAfee.

    See project
  • Microsoft Internet Explorer

    -

    As part of the Microsoft Internet Explorer team, I helped ship version 3.0, 4.0, 5.0, 5.5 and 6.0.

    See project
  • Microsoft Windows

    -

    As a member of the Microsoft Windows team, I helped ship Windows 98, Windows 2000 and Windows XP.

    See project
  • Team Professor

    -

    With 60+ courses, TeamProfessor provides security and development teams with computer-based training that encompasses the latest industry best practices in application security.

    See project
  • TeamMentor

    -

    TeamMentor integrates with static analysis tools, helping teams make more sense of scan results and make critical decisions to fix software vulnerabilities.

    See project

Recommendations received

17 people have recommended Jason

Join now to view

View Jason’s full profile

  • See who you know in common
  • Get introduced
  • Contact Jason directly
Join to view full profile

Other similar profiles

Explore top content on LinkedIn

Find curated posts and insights for relevant topics all in one place.

View top content

Others named Jason Taylor

Add new skills with these courses