Toronto · Application & AI/LLM Security

I secure the production AI systems I know how to build.

Six years of application security at a major bank, SAST, DAST, and SCA built into dev pipelines, now focused on AI and LLM security: prompt-injection defense, guardrails, and the OWASP LLM Top 10. I build production AI systems end to end, so I secure them the way an engineer would, from the inside, not the outside.

Available now · 1–2 year contract or full-time · Remote · Toronto / ET Download résumé (PDF)
6 yrsbank application security
SAST/DAST/SCAbuilt into dev pipelines
OWASPLLM Top 10 hardening
12smart contracts secured
How I work
  • Security is my background, so I build controls into the pipeline instead of bolting them on.
  • I hardened my own AI platform against the OWASP LLM Top 10: prompt injection, generated-code scanning, and guardrails.
  • A reviewed pull request is the only path to production. Nothing auto-merges.
  • I want to bring this security-first way of building into a team.
Background

Six years in application security at a major bank, embedding security testing directly into developer pipelines, so controls live in the pipeline by default.

Selected work
AI ops, secured · flagship

An autonomous ops platform

Agents diagnose failures and draft fixes as pull requests I approve. Hardened against the OWASP LLM Top 10, prompt-injection defense, a generated-code scanner, and a kill switch, so the automation can never act on its own.

How it works →
AI data platform

DevAlpha, an AI data platform

Ingests ~168 sources and uses LLMs to cluster ~20,000 opportunities into themes, served through an API and an MCP server.

On-chain security

A live, always-on financial product

An on-chain product where a security bug means real financial loss: 12 smart contracts in production handling real money, plus the transaction-integrity and reconciliation checks that keep it honest. Details on request.

What I work with
SAST / DAST / SCA Threat modeling OWASP LLM Top 10 Prompt-injection defense Secret management Secure SDLC CI/CD GitOps Docker Linux Python GCP Cloudflare LLM orchestration MCP

Get in touch

Open to application security and DevSecOps work, contract or full-time. Grab a time on my calendar, or find me on LinkedIn.