Weston Steimel
About Weston Steimel
Weston Steimel is a Senior Software Engineer at Anchore, specializing in enhancing automated tools for open-source vulnerabilities. He has extensive experience in software development across various companies, including Koch Supply & Trading and Flint Hills Resources, and holds a Bachelor of Science in Computer Science from Kansas State University.
Work at Anchore
Weston Steimel has been employed at Anchore as a Senior Software Engineer since 2022. In this role, he contributes to the development of tools aimed at enhancing software security and compliance. His work includes contributions to Anchore's SBOM generation tool, Syft, which focuses on improving software bill of materials processes. He also actively participates in the Python Packaging Advisory Database, working to enhance open-source security.
Professional Experience in Software Development
Weston Steimel has extensive experience in software development across various organizations. He worked at Koch Supply & Trading as a Principal Software Engineer from 2019 to 2022 and previously as a Quantitative Software Developer from 2016 to 2019. His earlier roles include Software Developer at Flint Hills Resources from 2012 to 2014 and IT Manager at Student Publications Inc. from 2009 to 2011. He also served as an Assistant Network Administrator at Fort Larned Usd 495 from 2007 to 2008.
Education and Expertise
Weston Steimel earned a Bachelor of Science (B.S.) degree in Computer Science from Kansas State University, completing his studies from 2007 to 2012. His technical expertise includes developing cloud-based Python applications using AWS services. He is proficient in programming languages such as Go, .NET, and Java, and has a strong interest in containerization technologies, particularly Docker.
Contributions to Open Source Security
Weston Steimel is actively involved in enhancing open-source security. He enhances automated triage tools for open-source vulnerabilities at Google's OSV platform and collects and organizes package metadata across various ecosystems to improve CVE matching. He has developed a personal PyPI repository generator to eliminate vulnerable packages and works on cleaning up inconsistencies in the NVD vulnerability database through personal experiments.