About
Senior InfoSec Engineer at Cloud.gov. Cloud platform security, identity federation, and compliance automation — the kind you can actually ship. Lately: making AI coding agents safe enough for government work, because the adversaries aren't waiting. Homelab enthusiast, reformed small-business technician, perpetual tinkerer.
Views are my own, not my employer's.
How I got here
My first computer was a Tandy 286 — the Radio Shack floor model. I upgraded it to Windows 3.1 using thirty-something floppies. By the late 90s I was on Geocities; by the early 2000s I was running a self-hosted PHP forum on a PC under my bed with 500+ users. That turned into a decade fixing computers for small businesses around Harrisburg, PA, which turned into infrastructure, which turned into security.
The pivot: recovering a graduate student's thesis from an MBR virus. Classic "I need help, here's pizza" situation. To this day, when a bad CVE drops, I bring pastries for the response team.
Career
- Cloud.gov
- Cloud security architecture and federal compliance for a FedRAMP Moderate platform: vulnerability management, security tooling, incident response, and the NIST 800-53 Rev 4 → Rev 5 transition. On top of the day job, I lead an initiative to build the guardrails that let federal developers use AI coding agents safely.
- NIH
- Tier III support for federal medical research → security engineering for enterprise IT and genomic research infrastructure → enterprise vulnerability management across 100,000+ assets and 27 Institutes, including leading the Log4j response → HPC site reliability for a molecular-dynamics cluster. Got to burn in 8-way H100 nodes.
- Small-business IT
- An electronics refurbisher handling IT asset disposition for data centers: workstation, laptop, and server hardware of every vintage — firmware to OS — fixed and rebuilt at volume, plus data destruction that actually destroys data (degauss, shred, or wipe). Then a SaaS support team spanning five time zones, and MSP incident response.
- Independent consultant
- House calls to infrastructure management. A decade of learning how things break in the real world.
How I think about security
Security should enable work, not block it. The best controls are invisible: users never notice them because they just work. If developers can't deploy their code, they'll find a workaround. Make the secure path the easy path.
Automation isn't about replacing people. It's about freeing them from clicking buttons so they can do interesting work. AI security is about governance as much as tech: the hard problems are the humans, policies, and processes around the models. And attackers already use AI — defenders should get it too, with guardrails instead of workarounds.
Outside work
My homelab grew from one Raspberry Pi in 2015 to a Dell PowerEdge R910, a fleet of Pis, and far too many containers. I run my own SIEM, a self-hosted password manager, and whatever I'm experimenting with that week. I've burned out a GPU pushing local LLM inference too hard and taken down my home network for hours trying VLAN segmentation just to see how it works.
I'm deep into AI/LLM experimentation — running models locally, building multi-agent orchestration, and figuring out how to secure these systems in production. See the current stack on uses, what I'm building on projects, and what I'm focused on right now on now.
the workbench, roughly to scale
Theme credits
The terminal theme picker in the masthead runs on a curated subset of myoklch-terminal-themesdataset — 545 terminal color schemes converted to OKLCH, derived fromiTerm2-Color-Schemes (MIT) and the upstream theme projects. Palettes offered here:
- Dracula — upstream source
- Nord — upstream source
- Catppuccin Mocha — upstream source
- TokyoNight — upstream source
- Gruvbox Dark Hard — upstream source
- Kanagawa Wave — upstream source
- Rose Pine — upstream source
- Solarized Dark Higher Contrast — upstream source
- GitHub Light Default — upstream source
- Gruvbox Light Hard — upstream source
- Catppuccin Latte — upstream source
- Nord Light — upstream source