Security engineer focused on cloud infrastructure security and AI agent security.
MS Cybersecurity Engineering @ USC (Jun 2027) · prev. Security Engineer @ Systex (Splunk SIEM, 15 enterprise clients)
agent-policy-gateway— reference-monitor gateway for AI agent tool calls: YAML policies + taint-tracking information-flow control that blocks indirect prompt-injection exfiltration. On PyPI, OIDC trusted publishing.tracesig— Sigma-style detection rules for AI agent tool-call traces: open YAML rule format, reference engine, and a 12-rule starter pack covering prompt injection, exfiltration, privilege, and anomaly patterns. On PyPI.llm-canary— canary tokens for LLM contexts to catch prompt injection and context exfiltration.- Interned on a security team building a zero-trust AWS platform: eliminated all public SSH across dev/prod (Tailscale subnet routers + ephemeral CI nodes), designed 12h JIT access to production, rolled out GuardDuty/Inspector/Prowler across a multi-account org.
- Co-author, IEEE Access (2025): TIRDH — reversible data hiding algorithm.
