Services

I work best on security problems where a written scope, reproducible evidence, and a clear fix path matter more than noisy scanner output.

Engagement Types

Security Review & Audit

Scoped application, platform, or workflow review with prioritized findings, reproduction notes, and remediation guidance.

Purple-Team Lab Design

Repeatable lab ranges, detection exercises, telemetry plans, and training material for realistic but controlled practice.

DevSecOps Automation

Validators, deployment guardrails, redaction checks, static reports, and operator workflows that make risky handoffs safer.

AI-Assisted Operations

Local-first agent workflows, knowledge-RAG patterns, approval gates, and sensitive-data boundaries for internal automation.

What You Get

  • A clear scope statement before testing or implementation starts.
  • Reproducible notes, evidence references, and prioritized remediation advice.
  • Practical handoff documentation written for the team that has to maintain the fix.
  • External summaries only when disclosure rules and client boundaries allow it.

Good Fit

  • Small teams that need security work to be concrete and actionable.
  • Engineering-heavy environments where infrastructure, CI, identity, and application risk overlap.
  • Teams building internal labs, detection exercises, or approval-aware automation.

Not A Fit

  • Unsanctioned testing, denial-of-service work, or social engineering.
  • Work without written authorization and clear target boundaries.
  • Engagements that need a large consultancy bench instead of a focused operator.

Start A Conversation

Use Contact for the current public contact paths.