I design security architecture for cloud-native production systems, and I build open-source tooling for securing AI and agentic systems. 8+ years across security engineering, cloud infrastructure, and networking.
- 🛡️ Fleet-wide CI/CD security pipelines, container hardening, IaC platform services, and TLS automation in a regulated healthcare environment (ISO 27001, GDPR).
- 🤖 Securing LLM and agentic systems — mapped to OWASP LLM Top 10, MITRE ATLAS, and the NIST AI RMF.
- 🔎 Detection engineering, incident response, vulnerability management, and compliance-aligned remediation.
- USAP — Unified Security Agent Platform: 79 security skills and 12 orchestrator agents over the Model Context Protocol, mapped to MITRE ATT&CK, MITRE ATLAS, OWASP LLM Top 10, and NIST AI RMF. Typed output contracts, resolvable-evidence gating, hash-chained audit log, tiered autonomy (L1–L4) behind human approval gates. → usapsec.vercel.app
- ARIA — autonomous, fully-local penetration-testing research agent: a typed decision engine, loadable security skills, and an immutable audit ledger, in evaluation against DVWA and OWASP Juice Shop. Research preview.
- ssh-ssl-auto-renew — automated SSH key and TLS certificate rotation with validation, failure-mode handling, and rollback.
- cloud-node-pod-cleanup-tool — OpenStack + Kubernetes operational-security automation with guardrails.
- 15+ production repositories on one CI/CD security architecture — Semgrep SAST, OWASP ZAP DAST, npm-audit SCA, Trivy container/IaC scanning, Gitleaks secrets detection, every scanner image pinned by SHA-256 digest.
- Zero HIGH/CRITICAL CVEs in production images — cleared 29 HIGH and 6 CRITICAL from the primary base image, enforced non-root containers fleet-wide.
- TLS lifecycle fully automated — scheduled pipelines renew and deploy certificates to every host over WireGuard and rotate cloud load-balancer certificates via API.
- 99.99% uptime on banking-technology infrastructure; 30% reduction in network downtime; 17% production-efficiency gain via an AWS migration delivered through infrastructure-as-code.
Securing AI and agentic systems on cloud — a secure LLM inference pipeline on AWS (Terraform IaC, least-privilege IAM, private networking, CI security gates, prompt-injection guardrails), cloud-security guardrails as code (Checkov + OPA/Conftest policy-as-code with drift detection), and an agentic-AI red-team lab (garak, PyRIT, promptfoo mapped to OWASP LLM Top 10 and MITRE ATLAS). Alongside a structured 12-Month Security Engineering Journey.
| Role | Company | Period |
|---|---|---|
| DevSecOps Engineer (Cloud Security) | LINDERA | Apr 2025 – Present |
| Cybersecurity & DevOps Engineer (Working Student) | LINDERA | Oct 2023 – Mar 2025 |
| NOC Engineer II | Zeta | Oct 2019 – Mar 2023 |
| Associate Network Engineer | KocharTech | Sep 2016 – May 2019 |
Open to Cloud Security Engineer, DevSecOps Engineer, and AI Security Engineer roles — Berlin or remote.


