@@%*-. -*#%%@@@@@@@@@%#+: .-*
%+: .+@@@@@@@@@@@@@@@@@%*
. -#@@@@@%%@@@@@@@@@@@@@#.
#@@%*+==-=+*##*==*#%@@@+
#@#=::::....::...:-=*%@*
+%*--::::::..:::::--=#%=
-#=--::..........::--+%.
:*-=+++=-:....:-===+==#.
:--=++*===-::-==+*++==+:
:::::::::::.:::::------.
:::.....::...-::....::-.
.-:.....:--:---.....:--.
.::::::-----=-:::::--.
--:-++=-::--=++-:--:
:=--::-------::--=-
.==+=-::::::-===++:
-=*#**+===+*%#*+=.
:::::=+*######*+-:-:
.-:.. ...:::::::...:-.
. ..
Senior AI Application Security Engineer with 11+ years securing web, API, cloud-native, and AI-enabled systems across airlines, telecom, consulting, and financial services. I'm a builder, not just an auditor — I come from a production Python/Java development background and specialize in LLM security, prompt injection defense, agentic system trust boundaries, and AI-assisted development security.
- 🛡️ Own SAST/SCA/DAST pipelines end-to-end (Veracode, Checkmarx, Snyk, Semgrep, Burp Suite, OWASP ZAP)
- 🤖 Secure agentic & LLM systems — prompt injection defense, jailbreak resistance, MCP scope governance, agent credential inheritance
- 🧵 Run enterprise threat modeling programs using STRIDE
- ⚙️ Build AI-assisted dev security tooling — deterministic gates for agent-generated code, Claude Code/Copilot/Cursor governance
- ☁️ Design secure cloud-native architectures on AWS/GCP with IAM, KMS, Kubernetes/OpenShift
Responsible disclosure researcher (GitHub Security Advisories) against major open-source projects:
- open-webui/open-webui — Client-side SSRF via chart rendering (CWE-918) — Acknowledged, CVE pending
- langgenius/dify — Cross-tenant IDOR, unauthenticated impersonation, and info disclosure (3 findings)
- mkdocs/mkdocs — Unsafe YAML deserialization, stored XSS, path traversal, and more (6 findings)
- goauthentik/authentik — SAML XML signature wrapping, OAuth2 redirect_uri binding issue
- FlowiseAI/Flowise — Mass assignment enabling billing field overwrite
- burp-jwt-analyzer — Burp Suite extension for detecting insecure JWT configs, weak validation logic, and token exposure
- Burp_LLM_Tester — Burp Suite extension integrating LLM reasoning into HTTP analysis, vulnerability triage, and API security automation
- StoryMagic — Full-stack generative AI storytelling platform (React Native + Node.js + Gemini) with content moderation and hallucination mitigation baked in
- TokenTenancy — Full-stack rental/tenant management platform with secure auth, RBAC, and hardened API workflows
Pin these on your profile for best visibility: burp-jwt-analyzer (already public), plus Burp_LLM_Tester, StoryMagic, TokenTenancy once those repos are public. Go to a repo → the "⋯" menu (or your profile's Customize pins) → Pin repository.
Languages: Python · Java · FastAPI · Bash Security Tools: Veracode · Checkmarx · Snyk · Semgrep · Burp Suite · OWASP ZAP · Sonatype Nexus · Prisma Cloud · Wiz Infra: Kubernetes/OpenShift · Docker · Terraform · Helm · GitLab CI/CD · Jenkins · Tekton Cloud: AWS (IAM, KMS, GuardDuty, Security Hub) · GCP AI/LLM Security: Prompt injection defense · Adversarial testing · OWASP Top 10 for LLMs · AI red teaming
OSCP · CCSP · CEH · Red Teaming LLM Applications · Certified API Security Analyst · Red Team Ops (Zero Point Security) · Databricks Generative AI · Generative AI on AWS Bedrock & SageMaker
🎓 MS, University of Maryland–Baltimore County
