Natalie Somersall
🗺️ Washington, DC metro area
✍🏻 Blog - https://some-natalie.dev
🎤 Speaking - https://some-natalie.dev/speaking
👩🏻💻 GitHub - https://github.com/some-natalie
💼 LinkedIn - https://www.linkedin.com/in/nsomersall
Booz Allen Hamilton - Senior Lead AI Software Engineer, 2026-present
- What does the future of AI-powered software development look like for the Defense Industrial Base? How do we secure it, from human to AI agent to delivery?
XBOW - Public Sector Technical Leader, 2026
- Lead an AI-powered cybersecurity solution as the first hire for the market. Mentor and ramp teammates from commercial sales into the Federal market.
Chainguard - Public Sector Field CTO (Senior Principal), 2024-2026
- Build Public Sector sales as the first engineer dedicated to the vertical. Ramp and mentor the team to over 50 people supporting public sector go-to-market, each with growing territories to drive tens of millions in revenue from greenfield.
- Lead first-of-its-kind proof of concepts on complex migrations into containerized workloads, regulated artificial intelligence (AI) applications, promotion across air-gaps and other compliance boundaries as needed, and adoption of FIPS-validated cryptography.
- Demonstrate business value of application security and software supply chain best practices to a myriad of regulatory frameworks and guidelines, now including NIST Secure Software Development Framework and Application Container Security Guide .
- Executive briefings and thought leadership to support a rapidly-growing technology and audience.
GitHub - Senior Solutions Engineer, 2021-2024
-
Partner exclusively with the most security-conscious customers, guiding them on meeting their development and security needs within the entire GitHub Enterprise platform and integrations.
- Evaluating and securely deploying artificial intelligence (AI) across the development lifecycle, then assessing business and application security impacts
- Automating and building the infrastructure to support it safely
- Cultural changes of internal collaboration and rolling out application security programs
- Deployment and compliance planning (eg, CMMC, FedRAMP, ITAR) of enterprise software factories
- Consistent quota attainment of over 150% every half.
- Develop custom solutions such as human-friendly Kubernetes runners or managing an enterprise-wide security team across the largest GitHub customers.
- Thought leadership, speaking and writing about developer problems within regulated industries, and customer advocacy within our Product and Engineering teams.
- Mentorship throughout the solutions team to ensure continued career and sales growth.
Booz Allen Hamilton - Lead Engineer, 2015-2021
-
Lead consolidation of developer tools within CMMC and ITAR compliance including:
- Plan of Action and Milestones (POA&M) management for enterprise-wide systems
- Application security tools to centralized reporting within Cybersecurity Team
- Source control to GitHub Enterprise Server (several thousand active users)
- CI/CD to GitHub Actions in on-premises bare-metal Kubernetes
- Custom audit reports, saving thousands of dollars per year on audits per consolidated system
- Drive adoption via migration, support, and community engagement
- Develop a data lake for actionable business insights into developer productivity, tool adoption trends across several dozen sources, and talent planning.
- Lead a team for Linux infrastructure operations for Cybersecurity and Incident Response supporting threat hunting, insider risk, penetration testing, incident response, and vulnerability management.
- Develop infrastructure for exploratory AI/ML workloads with white-box GPUs and custom Linux kernel versions (similar to fedora-acs-override ) for effective scheduling across tenants.
-
Create critical cross-team business processes for software development firm-wide.
- Open-source license risk assessment and mitigation
- Automated compliance auditing and alerting for developer tools
- Revamp the process to open-source internally developed software
- Consolidate Global Hosting Services environments via Rundeck, vSphere, and SaltStack.
Related experience
- 🛠️ Container Escapes 101 (August 2026), an interactive workshop at the AppSec Village at DEF CON 34 . Let’s figure out if we’re in a container and try some escapes live! (link , writeup and demos)
- 🎙️ There I FIPS’d It - Misadventures in Federal Cryptography (January 2026) at DistrictCon 1 . Cryptography seems deceptively simple until you get into implementation. It’s tempting to ship something “just good enough”. We’ll tour the most common footguns I find in the field with folks who are sure they’ve done it right, with live demos and example code. (link , slides with writeup)
- 🎙️ Signing and Verifying Multi-Architecture Containers with Sigstore (June 2025) at OpenSSF Community Day NA 2025 . We’ll run through real-world weirdness managing multi-architecture images at scale, including how some registries and pull-through caches behave unexpectedly with other enterprise software. (slides with writeup, YouTube )
Education
- Master’s of Science in Engineering from Virginia Tech
- Bachelor’s of Science in Engineering from Virginia Tech , double major
Related prior employment, references, and other information available upon request.