Security engineering with a working lab behind it.
I build scoped security reviews, purple-team lab infrastructure, and automation-backed remediation workflows for teams that need evidence instead of theater.
Services
I am most useful where security, infrastructure, and automation overlap: findings need to be reproducible, defenses need to be observable, and the fix path needs to survive handoff.
Security Review & Audit
Application, platform, and workflow review with scope boundaries, reproducible evidence, and prioritized fixes.
Purple-Team Lab Design
Repeatable ranges, detection exercises, telemetry plans, and documentation that make security practice measurable.
DevSecOps Automation
Scripts, validators, deployment guardrails, and operator workflows that reduce manual drift and risky handoffs.
AI-Assisted Operations
Local-first agent workflows, knowledge-RAG patterns, approval gates, and redaction-aware automation for sensitive environments.
Selected Work
SAGA Purple-Team Platform
Overview of the lab-backed range used to validate attack paths, telemetry, evidence capture, and AI-assisted operator workflows.
WordPress Full-Chain Lab
A sanitized chain from initial web weakness through evidence, detection opportunities, cleanup, and remediation guidance.
Architecture Notes
External-facing decisions about local-first AI routing, redaction boundaries, capability servers, and static publishing.
Writeup Archive
Older CTF and technical walkthroughs retained as a learning archive, separate from current research positioning.
What's Here
- Services: How I scope work, what I deliver, and where I am a good fit.
- Research: Authorized security methodology, scope rules, and sanitized findings.
- Lab and SAGA: Sanitized lab notes and platform overview.
- About and Contact: Profile, links, and ways to reach me.
Public pages are intentionally scrubbed for secrets, private telemetry, internal host details, and live operator runbooks.