I secure the production AI systems I know how to build.
Six years of application security at a major bank, SAST, DAST, and SCA built into dev pipelines, now focused on AI and LLM security: prompt-injection defense, guardrails, and the OWASP LLM Top 10. I build production AI systems end to end, so I secure them the way an engineer would, from the inside, not the outside.
- Security is my background, so I build controls into the pipeline instead of bolting them on.
- I hardened my own AI platform against the OWASP LLM Top 10: prompt injection, generated-code scanning, and guardrails.
- A reviewed pull request is the only path to production. Nothing auto-merges.
- I want to bring this security-first way of building into a team.
Six years in application security at a major bank, embedding security testing directly into developer pipelines, so controls live in the pipeline by default.
An autonomous ops platform
Agents diagnose failures and draft fixes as pull requests I approve. Hardened against the OWASP LLM Top 10, prompt-injection defense, a generated-code scanner, and a kill switch, so the automation can never act on its own.
How it works →DevAlpha, an AI data platform
Ingests ~168 sources and uses LLMs to cluster ~20,000 opportunities into themes, served through an API and an MCP server.
A live, always-on financial product
An on-chain product where a security bug means real financial loss: 12 smart contracts in production handling real money, plus the transaction-integrity and reconciliation checks that keep it honest. Details on request.
Get in touch
Open to application security and DevSecOps work, contract or full-time. Grab a time on my calendar, or find me on LinkedIn.