Work
Things I've built, with a link to the public artifact where there is one. The résumé covers the rest.
Projects
67IPAM pools · 874 resources
Multi-Region IPAM on AWS
Multi-account, hierarchical IP address management automated end-to-end in Terraform, with cross-account sharing via AWS RAM. I authored the public AWS Prescriptive Guidance pattern for this architecture and open-sourced the Terraform to aws-samples.
- 67 hierarchical pools
- 874 network resources
- Terraform
- AWS RAM
AWS Prescriptive Guidance patternaws-samples on GitHubDeep dive
2 wk → 4 hsecurity validation turnaround
Shift-Left DevSecOps Automation
A CI suite orchestrating 15+ SAST/DAST/IaC/secrets scanners that only scan what changed. Cut a financial-services platform's security validation from two weeks to four hours.
- 15+ scanners (Bandit, Semgrep, Checkov, Trivy, tflint, GitLeaks…)
- GitHub Actions
- 40–60% CI cost reduction
- SARIF to GitHub Security
The write-up
127threats modeled and remediated
GenAI & Agentic-AI Security
Security for LLM and agentic systems: OWASP LLM and Agentic Top 10 reviews, MCP and multi-agent architecture security, and an AWS-internal tool (IAMulator) that generates least-privilege IAM policies from natural language. Threat-modeled and helped remediate 127 threats in a FINRA-approved GenAI platform.
- OWASP LLM & Agentic Top 10
- MCP / multi-agent
- IAMulator (AWS-internal)
- 127 threats
Related: the security side of vibe coding
Things I run
- nhl.scyber.ai: a Colorado Avalanche stats site. It rebuilds every night: an EventBridge-scheduled Lambda pulls the NHL public API and MoneyPuck, computes paces, record chases, and career milestones, and writes one JSON file to S3. The page is plain HTML and four ES modules (no framework).
- ruthevelynpaints.com: my fiancée Kayla's art portfolio. A static site plus serverless form handling on AWS, all of it in Terraform.
- scyber.ai: this site. S3, CloudFront, Route 53, WAF, Terraform, GitHub Actions with OIDC, and CloudWatch alarms that email me.
Also
Cloud governance and compliance-as-code in regulated AWS environments: Service Control Policies, AWS Config custom rules (Guard DSL), Security Hub, GuardDuty, Control Tower and Landing Zone Accelerator baselines, against HIPAA, HITRUST, PCI DSS, SOC 2, NIST 800-53, and FedRAMP. None of that is public. The résumé covers it by role.
← Home