Selected work

Systems for security engineering.

Focused project narratives at the intersection of application security, automation, and production software.

Project index

Platform thinking, translated into products.

Each case study connects the problem to role, constraints, architecture, security decisions, and current status.

01 / Security automation platform

VulnScope

Flagship case study

Role
Product and platform engineering
Constraint
Workspace tenancy, canonical asset identity, durable state, and bounded scanner execution.

Problem

Black-box security scanning creates coordination work across assets, tools, execution stages, and result types.

Architecture

A PostgreSQL-authoritative scan platform with transactional dispatch, Celery workers, and normalized scanner results.

Security decisions

Tenant isolation, rotating refresh sessions with replay protection, and explicit scanner safety boundaries.

Result / impact

Turns scanner execution into an inspectable workflow while keeping findings distinct from lower-confidence observations.

02 / Professional application security

Security Automation Platform

Generalized professional case study

Role
Sr. Application Security Engineer
Constraint
Different application shapes, Kubernetes-based infrastructure, Skaffold environments, and confidential findings.

Problem

Enterprise DAST workflows had to support monolithic and service-oriented applications across HTTP and gRPC interfaces.

Architecture

Coordinated Burp Suite, OWASP ZAP, and grpcurl workflows with operational design, review, and rollout planning.

Security decisions

Environment preparation, controlled tool execution, protected finding review, and no exposure of internal topology.

Result / impact

Produced reusable scanning workflows, technical documentation, and organization-level DAST rollout plans.

03 / Controlled security simulation

Engarde

Case study available

Role
Founding Software Engineer
Constraint
Authorized use, controlled environments, real-time state, telemetry, and safe public disclosure.

Problem

Distributed network attack scenarios need a controlled product environment for authorized simulation, observation, and assessment.

Architecture

A full-stack cyber range combining orchestration, monitoring, telemetry collection, analytics, and reporting.

Security decisions

Defensive testing only, with authorization and environmental scope treated as product boundaries.

Result / impact

Delivered platform capabilities for real-time simulation control and evidence-based assessment workflows.

  • Full-stack platform
  • Real-time orchestration
  • Telemetry
  • Analytics
  • Reporting
Read case study