Not Another Padlock

30 years of security innovation. Standards that shaped the internet. When outcomes are too important to trust to just vibes.

About

I'm Brad Hill, and I've spent three decades building security technologies and standards that billions of people use every day. From leading working groups at the W3C to security architecture at Meta, from pioneering FIDO authentication to inventing protocols that protect how you recover your accounts — I've seen firsthand what it takes to build security products that actually work.

When Facebook's design team asked for logo ideas for a new account recovery product, I told them "just not another padlock," because it wasn't like anything else in the market. That's what my work at Not Another Padlock is about: helping you take big swings at hard problems and deliver actual innovation.

I'm available for full-time and part-time engagements in the Seattle area or remotely. Whether you're ideating a new product, refining requirements, architecting security, managing execution, or verifying pre-launch — I can help you build something that actually matters.

What I've Built

30+
Years in Internet Security
1B+
Users Impacted
15+
Standards Specifications

Key Contributions

W3C Web Application Security

Help found and co-led the working group that created Content Security Policy, Subresource Integrity, and Credential Management, now fundamental to web security.

FIDO Alliance

Key technical contributor to the FIDO Alliance v1 specifications that laid the foundation for the Passkeys standard that's replacing passwords.

Crisis Leadership

Led Facebook Login's response during the Cambridge Analytica crisis. Rebuilt product privacy posture in weeks while maintaining team stability and trust.

Platform Security Architecture

Architected security for products serving billions. Led GDPR rollout, HTTPS-only migration, incident response, and innovation during major platform transitions.

Technical Innovation Under Pressure

When Apple's privacy changes threatened to shut down Facebook Login, I invented a new technical approach that saved the product and evolved with market demands.

Talent Development

Built high-performing teams from the ground up. Mentored dozens of engineers to senior levels. Known for developing talent through complex, high-stakes projects.

How I Can Help

Every engagement is tailored to your specific needs. I work across the full product lifecycle:

Product Ideation & Vision

Help you think through what's actually worth building. Identify how to deliver customer value. Integrate the economics and incentives of multi-party markets with the technical possibilities for your product.

Requirements & Architecture

Define what secure, compliant, and user-friendly actually means for your product. Real threat modeling, not checklist security.

Product Specification

Write the blueprints that engineers and agents can build from. Make security requirements testable and clear.

Standards & Compliance

Navigate W3C, FIDO Alliance, IETF, CA/Browser Forum, GDPR, and emerging regulations. I've been part of these conversations for decades.

Project Planning & Execution

Help you scope the work, manage timelines, handle dependencies across teams, and keep projects on track through complexity.

Engineering Leadership

Take on technical leadership roles. Build teams, mentor senior engineers, set technical direction under pressure.

Documentation & Knowledge

Make your security posture, threat model, and architecture understandable to everyone who needs it.

Launch & Verification

Security review before launch, incident response planning, and post-launch support.

Special focus: I bring particular value to organizations navigating privacy regulations, building authentication and identity products, adopting new security standards, responding to security incidents, or making major technical pivots. I'm equally comfortable working solo on specific projects or embedded as part of a larger team.

Engagement Options

Location: Based in Seattle, available for in-person engagement in the Pacific Northwest or fully remote work. Let's talk about what works best for you.

Let's Build Something Worth Building

If you're working on security, privacy, authentication, identity, or standards-driven products—and you want someone who's actually shaped the landscape—let's talk.

Get in Touch

Email: hillbrad@notanotherpadlock.com

LinkedIn: linkedin.com/in/brad-hill-00a2891

Location: Seattle, WA | Remote-friendly