Work

Things I've built, with a link to the public artifact where there is one. The résumé covers the rest.

Projects

67IPAM pools · 874 resources

Multi-Region IPAM on AWS

Multi-account, hierarchical IP address management automated end-to-end in Terraform, with cross-account sharing via AWS RAM. I authored the public AWS Prescriptive Guidance pattern for this architecture and open-sourced the Terraform to aws-samples.

  • 67 hierarchical pools
  • 874 network resources
  • Terraform
  • AWS RAM
2 wk → 4 hsecurity validation turnaround

Shift-Left DevSecOps Automation

A CI suite orchestrating 15+ SAST/DAST/IaC/secrets scanners that only scan what changed. Cut a financial-services platform's security validation from two weeks to four hours.

  • 15+ scanners (Bandit, Semgrep, Checkov, Trivy, tflint, GitLeaks…)
  • GitHub Actions
  • 40–60% CI cost reduction
  • SARIF to GitHub Security
127threats modeled and remediated

GenAI & Agentic-AI Security

Security for LLM and agentic systems: OWASP LLM and Agentic Top 10 reviews, MCP and multi-agent architecture security, and an AWS-internal tool (IAMulator) that generates least-privilege IAM policies from natural language. Threat-modeled and helped remediate 127 threats in a FINRA-approved GenAI platform.

  • OWASP LLM & Agentic Top 10
  • MCP / multi-agent
  • IAMulator (AWS-internal)
  • 127 threats

Things I run

Also

Cloud governance and compliance-as-code in regulated AWS environments: Service Control Policies, AWS Config custom rules (Guard DSL), Security Hub, GuardDuty, Control Tower and Landing Zone Accelerator baselines, against HIPAA, HITRUST, PCI DSS, SOC 2, NIST 800-53, and FedRAMP. None of that is public. The résumé covers it by role.

← Home