Engineering teams I've worked with
Security and infrastructure work across Fortune 500 and growth-stage orgs.
I find where your security risk, pipeline drag, and cloud spend come from, then ship the fixes myself. You get merged pull requests with before-and-after numbers attached to them.
Most clients watch the first number move inside a month. Cuts of 60–90% in critical findings, CI/CD runtime, or cloud spend are typical.
I sit in your team chat and carry each issue from triage to merged fix. No report lands on your desk for someone else to action.
The work
-
Triage that survives scrutiny. I trace which findings an attacker can reach and hand you the 12 that qualify out of 800, each with a proof your engineers can run themselves.
-
CI/CD hardening and cost cuts. I pin actions, close privilege-escalation paths, and parallelize jobs. Your builds finish faster and stop leaking tokens.
-
Cloud cost surgery. I break your AWS bill down by service, team, and feature, then right-size the instances and kill the idle resources behind it. You see the difference on the next invoice.
-
SAST / DAST / IaC on every PR. I wire Trivy, Snyk, Grype, Checkov, and Nuclei into Actions, with gates tuned to block exploitable risk at the speed your team already ships.
-
AI & MCP security. I threat-model agentic systems, build prompt-injection guardrails, and monitor your MCP supply chain. Your scanners ship no rules for any of it.
Recent merges
Live from GitHub · merged pull requests · see what each one changed →
Work with me
Bring the repo, pipeline, or AWS bill that worries you most. One call to scope it, and you leave with a straight answer on whether I can move the number.





