Natalie Somersall
🗺️ Washington, DC metro area
✍🏻 Blog - https://some-natalie.dev
🎤 Speaking - https://some-natalie.dev/speaking
👩🏻💻 GitHub - https://github.com/some-natalie
💼 LinkedIn - https://www.linkedin.com/in/nsomersall
Booz Allen Hamilton - Senior Lead AI Software Engineer, 2026-present
- Build AI agents for security work under human control inside a regulated industry with a fleet of agentic workflows. These triage alerts for reachability, manage POA&Ms, review diffs for reintroduced vulnerabilities, and open remediation pull requests. Every agent is isolated, ephemeral, audited, scoped to least-privilege short-lived credentials and constrained outputs; none can approve or merge its own work.
- Create policy-as-code governance for GitHub Enterprise Server implementing SLSA v1.2 Source and Build Track Level 3 — Terraform-managed organization rulesets, Rego policy tests gating every plan, and per-commit in-toto verification summary attestations signed by AWS KMS.
- Automate the audit evidence nobody wants to gather by hand — nightly exports of live enforcement state into hash-chained, tamper-evident records, with configuration drift detected, reported, and reverted without human intervention.
XBOW - Public Sector Technical Leader, 2026
- Lead an AI-powered cybersecurity solution as the first hire for the market. Mentor and ramp teammates from commercial sales into the Federal market.
Chainguard - Public Sector Field CTO (Senior Principal), 2024-2026
- Build Public Sector sales as the first engineer dedicated to the vertical. Ramp and mentor the team to over 50 people supporting public sector go-to-market, each with growing territories to drive tens of millions in revenue from greenfield.
- Lead first-of-its-kind proof of concepts on complex migrations into containerized workloads, regulated artificial intelligence (AI) applications, promotion across air-gaps and other compliance boundaries as needed, and adoption of FIPS-validated cryptography.
- Demonstrate business value of application security and software supply chain best practices to a myriad of regulatory frameworks and guidelines, now including NIST Secure Software Development Framework and Application Container Security Guide .
- Executive briefings and thought leadership to support a rapidly-growing technology and audience.
GitHub - Senior Solutions Engineer, 2021-2024
-
Partner exclusively with the most security-conscious customers, guiding them on meeting their development and security needs within the entire GitHub Enterprise platform and integrations.
- Evaluating and securely deploying artificial intelligence (AI) across the development lifecycle, then assessing business and application security impacts
- Automating and building the infrastructure to support it safely
- Cultural changes of internal collaboration and rolling out application security programs
- Deployment and compliance planning (eg, CMMC, FedRAMP, ITAR) of enterprise software factories
- Consistent quota attainment of over 150% every half.
- Develop custom solutions such as human-friendly Kubernetes runners or managing an enterprise-wide security team across the largest GitHub customers.
- Thought leadership, speaking and writing about developer problems within regulated industries, and customer advocacy within our Product and Engineering teams.
- Mentorship throughout the solutions team to ensure continued career and sales growth.
Booz Allen Hamilton - Lead Engineer, 2015-2021
-
Lead consolidation of developer tools within CMMC and ITAR compliance including:
- Plan of Action and Milestones (POA&M) management for enterprise-wide systems
- Application security tools to centralized reporting within Cybersecurity Team
- Source control to GitHub Enterprise Server (several thousand active users)
- CI/CD to GitHub Actions in on-premises bare-metal Kubernetes
- Custom audit reports, saving thousands of dollars per year on audits per consolidated system
- Drive adoption via migration, support, and community engagement
- Develop a data lake for actionable business insights into developer productivity, tool adoption trends across several dozen sources, and talent planning.
- Lead a team for Linux infrastructure operations for Cybersecurity and Incident Response supporting threat hunting, insider risk, penetration testing, incident response, and vulnerability management.
- Develop infrastructure for exploratory AI/ML workloads with white-box GPUs and custom Linux kernel versions (similar to fedora-acs-override ) for effective scheduling across tenants.
-
Create critical cross-team business processes for software development firm-wide.
- Open-source license risk assessment and mitigation
- Automated compliance auditing and alerting for developer tools
- Revamp the process to open-source internally developed software
- Consolidate Global Hosting Services environments via Rundeck, vSphere, and SaltStack.
Related experience
- 🛠️ Container Escapes 101 (August 2026), an interactive workshop at the AppSec Village at DEF CON 34 . Let’s figure out if we’re in a container and try some escapes live! (link , writeup and demos)
- 🎙️ There I FIPS’d It - Misadventures in Federal Cryptography (January 2026) at DistrictCon 1 . Cryptography seems deceptively simple until you get into implementation. It’s tempting to ship something “just good enough”. We’ll tour the most common footguns I find in the field with folks who are sure they’ve done it right, with live demos and example code. (link , slides with writeup)
- 🎙️ Signing and Verifying Multi-Architecture Containers with Sigstore (June 2025) at OpenSSF Community Day NA 2025 . We’ll run through real-world weirdness managing multi-architecture images at scale, including how some registries and pull-through caches behave unexpectedly with other enterprise software. (slides with writeup, YouTube )
Education
- Master’s of Science in Engineering from Virginia Tech
- Bachelor’s of Science in Engineering from Virginia Tech , double major
Related prior employment, references, and other information available upon request.