Security engineer with 19+ years across fintech, startups, and F1 - open-sourcing tools that surface IAM trust paths and cloud misconfigs.
- 🔒 Security Engineering - IAM trust-path analysis, red & purple team work + tooling, cloud recon
- 📊 Observability & Data - eBPF, continuous profiling, OTel, LGTM stack, ClickHouse
- 🛠️ Infrastructure - Kubernetes, OpenTofu/Terragrunt, GitOps
- 🤖 AI Agents - building lightweight automation and custom LLM tooling
| Project | Lang | Description |
|---|---|---|
| spark | Go | Cloud recon - find publicly exposed AWS resources |
| trick | Go | Effortless AWS persistence via AssumeRole - red team credential rotation |
| veil | Go | Map hidden trust paths in your AWS IAM before they become security risks |
| Project | Lang | Description |
|---|---|---|
| lock | Rust | Safely pin GitHub Actions to commit SHAs |
| Project | Lang | Description |
|---|---|---|
| atlantis-gen-yaml | Go | Generate Atlantis project configs from Terragrunt files |
| aws-console | Go | Open the AWS Console from your CLI credentials, instantly |
| echo | Rust | Minimal WebFinger (RFC 7033) on Cloudflare Workers |
| uddf2vid | Rust | Telemetry HUD overlay for dive footage, parsed from UDDF logs |
| yaml2json | Go | Fast YAML → JSON converter |





