Skip to content
View pdbaumhart's full-sized avatar

Block or report pdbaumhart

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
pdbaumhart/README.md

Hi there, I'm Patrick Baumhart! πŸ‘‹

I'm a Product Governance Lead at a Big 4 Consulting Firm with 10+ years of experience leading engineering teams and designing cloud-native architectures. I specialize in accelerating enterprise compliance and SDLC checks while maintaining a deep passion for supply chain security and open source software (OSS) license compliance.

πŸ”— Connect with me

LinkedIn

πŸ’Ό What I Do

As a Product Governance Lead, I focus on:

  • Leading engineering teams to deliver secure, compliant solutions
  • Designing cloud-native architectures that scale with enterprise needs
  • Accelerating enterprise compliance processes and automation
  • Optimizing SDLC checks to balance security with development velocity
  • Building governance frameworks for product development at scale

πŸ” Supply Chain Security

I'm deeply passionate about securing the software supply chain - from source code to production deployment. My focus areas include:

  • Software Bill of Materials (SBOM) generation and management
  • Vulnerability scanning and remediation in CI/CD pipelines
  • Dependency analysis and risk assessment
  • Container security and image scanning
  • Code signing and artifact verification
  • Zero-trust security models for development workflows

πŸ“‹ OSS License Compliance

Open source software powers the modern world, and I'm committed to ensuring organizations use OSS responsibly and compliantly:

  • License scanning and compatibility analysis
  • Policy enforcement for OSS usage
  • Legal risk assessment for license obligations
  • Compliance automation in development workflows
  • Open source governance and best practices
  • SPDX and license documentation standards

πŸ› οΈ Technologies & Expertise

Languages & Frameworks:

  • Python - Automation, security tooling, and data analysis
  • TypeScript - Full-stack development and API design
  • Go - High-performance services and CLI tools

Cloud & Infrastructure:

  • Kubernetes - Container orchestration and cloud-native deployments
  • Docker - Containerization and microservices architecture
  • Cloud Platforms - AWS, Azure, GCP for enterprise solutions

Security & Compliance Tools:

  • SBOM Tools: Syft, SPDX-Tools, CycloneDX
  • Security Scanners: Snyk, OWASP Dependency-Check, Grype, Trivy
  • CI/CD: GitHub Actions, Jenkins, GitLab CI
  • Governance Platforms: Custom compliance automation solutions

🌱 Current Focus

  • Scaling governance frameworks for enterprise product development
  • Automating compliance checks in CI/CD pipelines
  • Building cloud-native security solutions with Kubernetes
  • Developing best practices for OSS license compliance at scale
  • Mentoring engineering teams on secure development practices

πŸ’¬ Let's Connect!

With 10+ years of experience in enterprise consulting and product governance, I'm always interested in discussing:

  • Enterprise compliance strategies and automation
  • Cloud-native architecture design and implementation
  • Supply chain security challenges in large organizations
  • OSS license compliance at enterprise scale
  • Team leadership and engineering best practices

Feel free to reach out on LinkedIn - I'd love to connect and share ideas!

Popular repositories Loading

  1. pdbaumhart pdbaumhart Public

  2. gh-cert-write-javascript-actions gh-cert-write-javascript-actions Public

    My clone repository

  3. supply-chain-firewall supply-chain-firewall Public

    Forked from DataDog/supply-chain-firewall

    Supply-Chain Firewall (SCFW) is a tool for preventing the installation of malicious npm and PyPI packages πŸ”₯

    Python