Paid engagements fund the free and low-cost work below. If you're low-income, an
immigrant, LGBTQIA+, or a nonprofit — reach out anyway. We'll figure it out.
◈
Security assessment & code review
Application and cloud security review, threat modeling, vulnerability triage and
remediation planning, and secure-SDLC guidance — findings written clearly enough for
engineers to act on.
✎
CV & résumé review + feedback
Honest, tactical review and feedback on your security résumé, portfolio, and project
write-ups — from someone who's hired and been hired in this field.
⚑
Training & mentorship
Breaking into security — especially for adults changing careers. Structured guidance,
lab paths, and honest expectations. Sliding scale and free tiers for those who need it.
◎
Consultation
AppSec / DevSecOps program review, threat modeling, vulnerability-management
strategy, supply-chain security, and secure-SDLC enablement for engineering teams.
⌘
Community & 2600
Meetups, talks, and workshops. I help run and support local hacker spaces and
2600 meetings — come learn, no gatekeeping.
✶
Nonprofit & activist tech
Threat modeling, OPSEC, and infrastructure hardening for organizers, journalists,
and nonprofits working under pressure.
⚗
Incident response & forensics
Malware analysis, incident response, and digital forensics (DFIR) — triage a breach,
reverse a sample, reconstruct what happened, and harden so it doesn't recur. Real cases:
Shai-Hulud (npm supply-chain worm), Mirai, and Monero cryptominers — isolation &
quarantine, analysis, IOCs, and recovery.
§
Expert witness & contracting
Security expert-witness work and testimony, plus longer-term contracting — clear,
defensible technical analysis for legal matters and sustained engagements.