I am a Cybersecurity Engineer with demonstrated security engineering, consulting, and research experience working with organizations in the public and private sectors to implement, audit, and scale their information security programs.
I am primarily interested in the reliability and security of large scale distributed software systems.
When not working, I enjoy playing soccer, discovering new mountain biking and hiking trails.
- Cloud & Application Security
- DevSecOps
- Privacy Engineering
- Information Security Management Systems (ISMS) Implementation & Auditing based on ISO 27001
- Cybersecurity Solutions Implementation
- Offensive and Defensive Cyber Security Tools, Techniques, and Procedures (TTPs)
- Security assessments & penetration testing, social engineering assessments, red/blue teaming.
- Systems Auditing
- Programming Languages: Shell, Python, PHP, Javascript
- Cloud: AWS, Terraform, Terraform Cloud
- Configuration Management: Ansible, Chef, Vagrant
- CI/CD: CircleCI, GitLab, Github Actions
- SAST: Sonarqube, Snyk, Checkmarx
- DAST: Rapid7 InsightAppsec, OWASP ZAP, Burp Suite, Stackhawk
- Policy-As-Code: Open Policy Agent (OPA), HashiCorp Sentinel