Security must be enforced before execution — not reviewed after the damage is done.
I design and evaluate security controls for AI systems that can reason, call tools, access sensitive data, and take autonomous action.
My work focuses on the emerging attack surface created by agentic AI: prompt injection, excessive agency, privilege escalation, unsafe tool use, identity and authorization failures, sensitive-data exposure, and weak runtime controls.
This GitHub documents my hands-on work across AI security, offensive security, defensive operations, vulnerability management, governance, and healthcare security.
| Domain | Focus |
|---|---|
| 🤖 Agentic AI Security | Agent threat modeling, tool-use security, authorization boundaries, runtime controls |
| 🔴 AI Red Teaming | Prompt injection, privilege escalation, adversarial testing, attack-path analysis |
| 🔵 Defensive Security | Detection engineering, incident response, security operations |
| 🛡️ AI Governance | NIST AI RMF, AI risk assessment, control design, governance architecture |
| ⚕️ Healthcare AI Security | HIPAA-aligned AI security, sensitive-data protection, high-impact system risk |
| Discovery, prioritization, remediation, validation, continuous improvement |
🛡️ A Security-First Multi-Agentic SOC
A controllable, auditable multi-agent system that triages security alerts using local LLMs — built so that a fully compromised model still cannot skip triage, bypass human approval, or reach a capability it was never granted.
💪 VIGIL
Runtime security for autonomous AI agents. Stops an AI agent from doing something dangerous — before it happens, not after.
🏥 Northstar Medical AI Deployment
An end-to-end simulation of safe and secure adoption of an internal, constrained agentic AI capability at the fictional healthcare enterprise Northstar Medical.
🔐 Meridian Atlas Security
Atlas is a deliberately vulnerable LLM claims-handling assistant for a fictional insurer. Everything else in this repo attacks it, controls it, measures whether the control held, watches for the control failing silently, and turns all of that into audit evidence.
Modern AI agents can hold credentials, access APIs, retrieve sensitive information, invoke tools, modify systems, and initiate downstream actions.
That changes the security model.
Traditional application security asks:
“Can an attacker compromise the application?”
Agentic AI security must also ask:
“Can an attacker manipulate the model into using legitimate authority for an illegitimate action?”
My work in this area focuses on security controls around:
- Prompt injection and indirect prompt injection
- Agent privilege escalation
- Excessive agency and unconstrained tool access
- Identity, authentication, and authorization for agents
- Cross-agent trust and delegation
- Sensitive-data exposure
- Human-in-the-loop control points
- Runtime policy enforcement
- AI-specific threat modeling
- NIST AI RMF-aligned risk governance
The attack surface is no longer only the infrastructure. It is the decision, the authority behind it, and the action that follows.
My next portfolio projects are focused on translating AI security concepts into demonstrable architectures, attacks, controls, and testing methodology across:
Agentic AI Red Teaming → adversarial testing of autonomous workflows
Runtime Authority Enforcement → controlling what agents are permitted to execute
AI Threat Modeling → modeling identities, tools, memory, trust boundaries, and attack paths
Healthcare AI Security → security architecture for AI operating around sensitive clinical data
AI Governance Engineering → translating frameworks such as NIST AI RMF into technical controls
AI security cannot stop at policy.
A governance document cannot prevent an autonomous system from executing an unsafe action. Effective AI security requires governance to be translated into technical boundaries that can be observed, tested, enforced, and audited at runtime.
My approach connects:
Governance → Threat Modeling → Architecture → Red Teaming → Runtime Controls → Detection → Continuous Assurance
The objective is not simply to build more capable AI.
The objective is to build AI whose authority remains bounded, observable, and defensible.
| Credential | Status |
|---|---|
| 🎓 PhD Information Technology | In Process |
| 🎓 M.S. Cybersecurity & Information Assurance | Completed |
| 🎓 BBA Business Analytics | Completed |
| 🏅 CompTIA PenTest+ | Certified |
| 🏅 CompTIA CySA+ | Certified |
| 🏅 ISC2 Certified in Cybersecurity (CC) | Certified |
| 🏅 Google Cybersecurity Professional Certificate | Certified |
| 🏅 Google Data Analytics Professional Certificate | Certified |
End-to-end vulnerability management lifecycle — from discovery through remediation validation.
Demonstrates practical experience with vulnerability identification, risk analysis, remediation workflows, and security program operations.
🚨 Security Operations & Incident Response
Hands-on security operations and incident response implementation.
Demonstrates the operational side of cybersecurity: identifying suspicious activity, investigating security events, and driving incidents toward containment and remediation.
Agentic AI Security AI Red Teaming LLM Security Runtime Security AI Governance NIST AI RMF Prompt Injection Threat Modeling Security Operations Incident Response Vulnerability Management Healthcare Cybersecurity
I am building this portfolio around one question:
How do we give autonomous AI systems useful capabilities without giving them uncontrolled authority?
If you're working on AI security, agentic systems, AI red teaming, security engineering, AI governance, or high-impact AI deployments, I'd be glad to connect.
Build Standards. Build Strength. Build What Lasts.