product security · devsecops · supply-chain defense · digital rights

I secure the software you rely on
and fight the systems that surveil you.

Senior DevSecOps and product-security engineer with over a decade hardening software, running vulnerability-management programs, and defending software supply chains. Off the clock: a digital-rights activist working to expose and roll back mass surveillance and extractive datacenter buildouts.

Available for consulting, contracting & expert-witness work — training, mentorship & CV reviews

10+ yrsecurity engineering & DevSecOps
DFIRmalware analysis, IR & forensics
supply chainnpm attack threat hunting
0trackers on this site

// about

Hi, I'm scrypt-kitty.

I've spent over a decade in security engineering and DevSecOps — leading product vulnerability-management programs, application security, and software supply-chain defense at scale. My day-to-day is the unglamorous, essential work: triaging and remediating vulnerabilities, hardening CI/CD pipelines, reviewing code and infrastructure, threat modeling, and responding to incidents.

I care about doing it honestly. Good security work means reproducible findings, ruling out false positives, and clear remediation the engineers who own the code can actually act on. I've built the programs, the tooling, and the training to make that happen — and hunted threats through live supply-chain attacks when it counted.

I'm also a digital-rights activist. The same instincts that secure systems make it plain how surveillance systems really work — and who they're pointed at. I believe technology should extend human freedom, not quietly ration it. That conviction shows up in who I help and what I fight.

  • Focus product & application security, vulnerability management, supply-chain security
  • IR & forensics malware analysis, incident response, digital forensics
  • Cloud AWS, Kubernetes, Terraform, HashiCorp Vault, CI/CD
  • Tooling Snyk, Semgrep, Trivy, OSV, SAST/DAST/SCA, Burp Suite
  • Langs Python, Go, Ruby, Node.js, Bash
  • Compliance SOC 2, HITRUST
  • Certs Security+, Network+, Linux+, LPIC-1

// experience

Selected work

A decade-plus across product security, application security, and infrastructure. Employers generalized by domain — details on request.

Supply-chain security & threat hunting

Senior DevSecOps at a real-time database vendor. Owned supply-chain security tooling and vendor rollout, and hunted threats live through the Shai-Hulud, qix, and S1NGULARITY npm attacks. Built org-wide repo enumeration and automated removal of vulnerable dependencies.

Product vulnerability management

Led the product vulnerability-management program at an enterprise identity platform — triage, remediation strategy, executive metrics, and cross-team coordination across engineering, IT, compliance, and customer success.

Application security programs

Principal AppSec engineer at a healthcare-data platform: ran bug-bounty and penetration-testing programs, built threat models, drove HITRUST compliance, and reviewed code and cloud infrastructure for security.

Infrastructure security & IR

Head of infrastructure & security at a health startup: stood up the security program, led a SOC 2 audit, ran incident response (including a cl0p zero-day), and migrated infrastructure to Terraform-managed AWS.

Security research & development

Security R&D engineering: DLP and MFA software, GeoIP anomaly detection, CI/CD pipelines to Kubernetes and OpenStack, and secrets management with HashiCorp Vault.

Secure SDLC & enablement

Shifting security left: dependency-vulnerability reporting in CI/CD, SAST/DAST/SCA evaluation, secure-code-review practices, and hands-on training for engineering teams.

// services

How I can help

Paid engagements fund the free and low-cost work below. If you're low-income, an immigrant, LGBTQIA+, or a nonprofit — reach out anyway. We'll figure it out.

Security assessment & code review

Application and cloud security review, threat modeling, vulnerability triage and remediation planning, and secure-SDLC guidance — findings written clearly enough for engineers to act on.

CV & résumé review + feedback

Honest, tactical review and feedback on your security résumé, portfolio, and project write-ups — from someone who's hired and been hired in this field.

Training & mentorship

Breaking into security — especially for adults changing careers. Structured guidance, lab paths, and honest expectations. Sliding scale and free tiers for those who need it.

Consultation

AppSec / DevSecOps program review, threat modeling, vulnerability-management strategy, supply-chain security, and secure-SDLC enablement for engineering teams.

Community & 2600

Meetups, talks, and workshops. I help run and support local hacker spaces and 2600 meetings — come learn, no gatekeeping.

Nonprofit & activist tech

Threat modeling, OPSEC, and infrastructure hardening for organizers, journalists, and nonprofits working under pressure.

Incident response & forensics

Malware analysis, incident response, and digital forensics (DFIR) — triage a breach, reverse a sample, reconstruct what happened, and harden so it doesn't recur. Real cases: Shai-Hulud (npm supply-chain worm), Mirai, and Monero cryptominers — isolation & quarantine, analysis, IOCs, and recovery.

Expert witness & contracting

Security expert-witness work and testimony, plus longer-term contracting — clear, defensible technical analysis for legal matters and sustained engagements.

// activism & transparency

Surveillance is a choice. So is resistance.

Automated license-plate readers, always-on cameras, and hyperscale datacenters are being installed faster than communities can consent to them. The tools of the watchers aren't magic — they can be understood, documented, and challenged. I document how these systems work, help people opt out, and support the fights to stop them.

Anti-surveillance / DeFlock

Mapping and resisting Flock and other ALPR/mass-camera networks. Know what's watching your street, and what your rights are.

Get involved →

Anti-datacenter / Project Raspberry

Hyperscale datacenters drain water and power from communities that never agreed to host them. Transparency on permits, resource use, and who really benefits.

Learn more →

Digital rights (EFF-aligned)

Privacy, encryption, and the right to tinker. I stand with the broader movement for civil liberties in a networked world.

eff.org →

Free & open-source software

The tools that keep people private and free are overwhelmingly FOSS. I use, support, and contribute back to the open-source projects the security community runs on.

My contributions →

// notes & resources

Field notes & links

Longer writing and activism updates live on dispatches — Project Raspberry, DeFlock / Flock Off, and the fight against mass surveillance.

DEF CON notes

Talk summaries, tooling I picked up, and things worth revisiting from the con. (Coming soon — add write-ups here.)

BSides notes

Regional BSides highlights and local scene recaps. (Coming soon.)

Getting into security

A no-BS starter path: labs (HackTheBox, TryHackMe, PortSwigger Academy), what to learn first, and how to build a portfolio without spending a fortune. (Guide in progress.)

// projects

Projects

What I build when I'm not securing other people's systems.

Shipping

In development

  • unicron-ce / unicron-ee ↗Open-core AI-SOC security platform — Community (open source) + Enterprise. Public repo coming soon.
  • Meatspace ↗An alternate-reality game — a near-future world that's for sale, and you're browsing it. Live & in progress; enter via JANUS.
  • UNDERWIRE ↗Independent hacker / 2600 tech & activism zine + meetup. Launching soon.

Open-source contributions

// resources

Resources

Sites worth your time — and your traffic.

Digital Rights & Privacy

Anti-Surveillance

HAM Radio

Hacking & Phreaking

Threat Intel

Zines & Collectives

Archive & Preservation

Organizing — Virginia

// contact

Reach out

Reach me via Linktree, or the captcha-gated email below. I aim to reply within a few days.

  • Email solve to reveal —