Head of Security Architecture · Agoda · Bangkok
Coleton Pierson
I make the secure path the easiest path.
Security architect and engineer with over a decade spanning offensive security consulting, security product engineering, and enterprise platform security. I lead security architecture at Agoda, shaping how a global travel platform protects systems that serve millions of people every day.
About
I lead security architecture at Agoda, shaping how we protect our systems across every IT domain at global scale. My focus is applying timeless security principles to modern platform engineering. Instead of relying on friction or red tape, I work with engineering teams to embed automated safeguards directly into our core platforms. The result is deep enterprise defense, easy compliance, and complete freedom for engineers to innovate at high velocity.
I started out at Praetorian as one of its earliest employees, joining while the company was still a handful of people and helping it grow to a team of more than fifty. There I ran penetration tests and security assessments for Fortune 500 companies and venture-backed startups, built the cloud security service line, and later moved into product engineering to build the company's security platform. One of those clients was Booking Holdings, and I was on the team that ran Agoda's first NIST Cybersecurity Framework assessment on site in Bangkok. A dinner with Agoda's CISO while I was on vacation in Thailand turned into a job offer, and I never really left.
At Agoda I began on the incident response team, designing the automation and alerting platform the team still runs on. From there I moved into securing the private cloud while it was in its infancy, then broadened to security architecture across the whole company. Today I set the long-term security vision, own the technical decisions behind our critical initiatives, and still get my hands dirty writing proofs of concept.
I grew up in Texas and studied computer science at The University of Texas at Austin. I have lived in Europe and across the United States, and Bangkok has been home since 2019. Outside work I host a regular meetup for CISOs and security leaders across Thailand, and I have helped a number of people from the West find their footing in the region's security industry.
How I work
-
Secure by default
Controls belong inside the platform, not in a review queue. When the golden path is also the secure path, security scales with the organization instead of against it.
-
Engineer the solution
Architecture that cannot be built is just a diagram. I prototype, read the code, and work alongside the teams who own the systems so the design survives contact with production.
-
Compliance as a byproduct
PCI DSS, GDPR, and SOX are outcomes of good engineering, not separate projects. Automated inventory and evidence keep auditors satisfied without slowing anyone down.
-
Reduce the attack surface first
Zero Trust across identity, network, and workload removes whole classes of risk. Every system that no longer needs to be trusted is one fewer system to defend.
Selected work
Things I designed, built, or led that changed how an organization operates.
-
Agoda
Zero Trust across every IT domain
Led the company-wide Zero Trust program spanning identity, network, endpoints, and workloads, significantly reducing the attack surface of a hybrid estate serving millions of daily users.
-
Agoda
Automatic PII and sensitive-data labeling
Built detection that classifies the personal and sensitive data flowing between services and labels each service with what it processes. Compliance and audit inventory became accurate by construction.
-
Agoda
Incident response and SOAR platform
Designed and shipped the enterprise alerting and incident response pipeline, with automated detection and response that a small team can drive directly from Slack and Teams.
-
Agoda
Security architecture principles
Established the architecture principles and governance frameworks the engineering organization builds against, cutting security incidents while raising developer velocity. Brought NIST and MITRE ATT&CK into daily practice.
-
Praetorian
Cloud security service line
Documented, launched, and led the firm's cloud security practice, and architected the company's own cloud infrastructure and the secure client collaboration platform.
-
Praetorian
Security products on Google Cloud
Architected a multi-tenant vulnerability management platform for Fortune 500 clients, an ML-based source code analysis pipeline, and the microservice patterns the engineering team adopted.
Experience
-
2019 – present
Agoda Bangkok
- Head of Security Architecture 2026 – present
- Principal Security Architect 2022 – 2026
- Senior Security Engineer 2019 – 2021
Enterprise-wide security architecture for a global travel technology company in the Booking Holdings family. Security strategy across hybrid infrastructure, Zero Trust, application security reviews for PCI and PII services, and the liaison between compliance and engineering for PCI DSS, GDPR, and SOX. Mentor and grow security architecture capability across engineering teams.
-
2022
Modern Stack Independent
- Security consultant May – Nov 2022
Risk-based security guidance and engineering for startups and independent companies: application assessments, enterprise security evaluations, incident response, and secure cloud automation.
-
2013 – 2018
Praetorian Austin, Texas
- Software Engineer 2017 – 2018
- Senior Security Engineer 2016 – 2017
- Security Engineer 2013 – 2016
- Summer Intern 2013
Early employee of a bootstrapped security consultancy that grew from a handful of people to more than fifty and a Series A. Penetration testing and security assessments for Fortune 500 companies and venture-backed startups, then product engineering. Built a cloud-based GPU password cracking service as an intern, and the remote assessment appliance clients used for internal testing.
-
2012 – 2016
The University of Texas at Austin Computer Science
Certified in Securing Containers and the Kubernetes Ecosystem.
Open source
Mostly Go, mostly security tooling. Everything lives at github.com/rfizzle.
-
log-collector
Go
Generic security log collector, usable as a CLI or a library, with sources for Okta, Google Workspace, Microsoft Graph, CrowdStrike Falcon, Duo, Akamai, SentinelOne, HackerOne, Nessus, and more.
-
shhh
Go
Natural-language-to-shell tool for the terminal.
-
concord
Java · off hours
A collection of independent Minecraft Fabric mods, each overhauling one vanilla system, with a shared design system and CI.
Contact
I am always glad to talk security architecture, platform engineering, or life in Bangkok. The best way to reach me is [email protected], or connect on LinkedIn.
Bangkok, Thailand · UTC+7