Engineering teams I've worked with
Security and infrastructure work across Fortune 500 and growth-stage orgs.
I focus on the areas with the most impact — not surface-level audits. Initially, this means identifying the primary sources of security risk, pipeline drag, and cloud spend in your stack. From there, I ship fixes directly, and provide proof of their effectiveness.
Most clients see meaningful results within the first month: 60–90% reductions in critical findings, CI/CD runtime, or cloud spend are typical outcomes.
I work embedded in your team (Slack / team chat), and handle issues end-to-end rather than handing off reports or recommendations.
What I actually do
-
Vuln triage that ignores the noise. Reachability-based prioritization. The 12 findings out of 800 that actually matter — with proof of exploitability, not CVSS theater.
-
CI/CD hardening and cost cuts. Pin actions, kill PPE risks, parallelize jobs, drop GitHub Actions spend. Pipelines that finish faster and stop leaking secrets.
-
Cloud cost surgery. AWS bill broken down by service, team, and feature. Right-sized infra, killed idle resources, fixed egress traps. Receipts in the next invoice.
-
SAST / DAST / IaC that runs on every PR. Trivy, Snyk, Grype, Checkov, Nuclei — wired into Actions with policy gates that block real risk and don't slow shipping.
-
AI & MCP security. Threat models for agentic systems, prompt-injection guardrails, MCP supply-chain monitoring. The stuff your current tooling doesn't cover yet.
Recent merges
Live from GitHub · merged pull requests · see what each one changed →
Work with me
If you're shipping fast and your security posture, pipeline cost, or cloud bill has gotten away from you — let's talk. One call to scope the problem, no slide decks.





