I build security-focused software, security automation, and security systems for understanding, detecting, validating, and responding to real-world threats.
My work spans endpoint security, detection engineering, security operations, application security, identity and Zero Trust, cloud-native infrastructure, offensive security, and security research.
| Area | Focus |
|---|---|
| Endpoint & Linux Security | eBPF, kernel telemetry, process monitoring, system behavior, endpoint visibility |
| Detection Engineering | MITRE ATT&CK, Sigma, behavioral detections, adversarial testing, detection validation |
| Security Operations | SIEM, SOAR, alerting, incident workflows, telemetry pipelines |
| Application & API Security | Secure design, code review, authentication, authorization, API testing |
| Offensive Security | Penetration testing, attack simulation, reconnaissance, exploitation, post-exploitation analysis |
| Vulnerability Research | Vulnerability discovery, root-cause analysis, security testing, proof-of-concept development |
| Exploit Development | Memory corruption, binary analysis, debugging, exploitation concepts, mitigation analysis |
| Identity & Zero Trust | Workload identity, mTLS, SPIFFE/SPIRE, policy enforcement, posture-aware access |
| Network Security | Network telemetry, protocol analysis, packet analysis, network detection |
| Cryptography & PKI | Cryptographic primitives, TLS/mTLS, certificates, key management, PKI |
| Cloud & Kubernetes Security | AWS, GCP, Azure, IAM, containers, Kubernetes workloads, infrastructure security |
| CI/CD & DevSecOps | Secure pipelines, dependency security, supply-chain security, automated security testing |
| Security Automation | Go, Python, Java, scripting, API integration, orchestration, security tooling |
| Security Architecture | Threat modeling, trust boundaries, secure architecture, defense-in-depth |
| Security Validation | Automated testing, regression testing, adversarial validation, benchmarking, evidence generation |
Linux Endpoint Detection & Response
An eBPF-based endpoint security platform combining kernel instrumentation, Go telemetry processing, behavioral detection, network visibility, operational controls, Prometheus metrics, and a SOC-oriented dashboard.
Focus: eBPF · Linux Security · EDR · Behavioral Detection · Network Telemetry · MITRE ATT&CK
Detection Engineering & Security Validation
A security detection engineering platform focused on attack simulation, adversarial testing, Sigma evaluation, detection validation, and repeatable security evidence.
Focus: Detection Engineering · Threat Simulation · Sigma · ATT&CK · Security Validation
Identity-Aware Zero Trust Access Proxy
A security-focused access gateway built around identity, cryptographic workload identity, mTLS, device posture, adaptive risk evaluation, policy enforcement, protected application access, and security auditing.
Security flow:
User / Workload
↓
Identity
↓
mTLS + JWT
↓
Device Posture
↓
Risk Evaluation
↓
Policy Engine
↓
ALLOW / DENY
↓
Protected Application
↓
Security Audit
Focus: Zero Trust · IAM · mTLS · SPIFFE/SPIRE · PKI · Vault · Policy Enforcement
Real-Time Security Telemetry & Detection
A streaming security analytics platform designed around high-throughput telemetry ingestion, stream processing, detection, and analytical storage.
Focus: SIEM · Kafka · Apache Flink · ClickHouse · Go · Python
Distributed Security Orchestration
A distributed SOAR platform demonstrating event sourcing, CQRS, durable security workflows, Kafka-based event processing, case sequencing, recovery, and automated response actions.
Focus: SOAR · Security Automation · Event Sourcing · CQRS · Kafka · Distributed Systems
Secure Platform Engineering · AI · OAuth
A full-stack management platform combining application engineering, authentication and authorization, OAuth integrations, AI-assisted workflows, analytics, management interfaces, CI/CD security, and containerized infrastructure.
Focus: Secure APIs · OAuth · AI Engineering · Kubernetes · CI/CD · Platform Security
Security Research & Technical Discovery
A security-focused research tool for discovering technically relevant GitHub peers and collaborators using technical signals rather than popularity metrics, with privacy-conscious and responsible-use controls.
Focus: Security Research · GitHub API · Python · Secure Web Applications · Responsible Automation
I approach security work as an engineering problem:
Understand → Design → Build → Test → Break → Validate → Improve → Document
I care about working implementations, measurable behavior, reproducible validation, clear security boundaries, and honest documentation of limitations.
- Endpoint and Linux security
- eBPF and kernel telemetry
- Detection engineering and adversarial validation
- SIEM and SOAR architecture
- Application and API security
- Secure software architecture
- Identity and Zero Trust
- Cloud, Kubernetes, and container security
- CI/CD and DevSecOps security
- Security automation and orchestration
- Vulnerability research and offensive security
- Penetration testing and attack simulation
- Exploit development and binary analysis
- Malware analysis and reverse engineering
- Network security and network telemetry
- Cryptography and applied security
- Security engineering for distributed systems
- Security testing, validation, and security tooling

