"I build secure systems and prove where they break, turning raw scanner noise and incident chaos into high-confidence engineering decisions."
I am an Application Security & Product Security Incident Response (PSIRT) specialist with 6+ years of experience securing enterprise cloud infrastructures and US government healthcare systems. My expertise spans:
- Incident Response & Triage: Resolving complex production security incidents, investigating exploit reachability, and coordinating cross-functional emergency patch lifecycles.
- Secret Governance & Remediation: Architecting enterprise-scale automated secret-leak remediation pipelines and TruffleHog governance workflows.
- Offensive Security & Red Teaming: Deep manual web/API penetration testing, business logic flaw exploitation, auth bypass, and evidence validation.
- AI-Driven Security Automation: Engineering autonomous AI security agents, custom Claude AI skills, and CVE correlation frameworks to accelerate vulnerability identification and triage.
- AppSec Governance & Secure SDLC: Implementing automated SAST/DAST/SCA gate checks, threat modeling, architecture reviews, and reducing scanner false-positive noise.
(May 2026 β Present)
- Incident Response at Scale: Spearheaded PSIRT operations across 100+ critical security incidents, streamlining cross-functional triage workflows to accelerate mean time to resolution (MTTR by 33%).
- TruffleHog Secret Invalidation: Orchestrated the enterprise-wide TruffleHog secret leak incident response lifecycle, reducing secret invalidation and credential revocation timelines from 70 to 38 days (45% reduction in exposure window).
- Autonomous AI Security Agents: Architected autonomous AI-powered PSIRT automation tooling, engineering custom Claude AI skills and a specialized CVE detection and response framework agent to automate vulnerability identification, exploit verification, and developer remediation workflows.
- Root-Cause & Governance: Led post-mortem investigations and risk-informed patch governance across distributed cloud services.
(Jun 2019 β May 2026)
- Top 1% Performance Rating: Recognized with the Outstanding Performance Award (Top 1%) for high-assurance cybersecurity delivery on US government healthcare systems.
- 30% False-Positive Reduction: Engineered unified correlation logic across SAST (Fortify SSC), DAST (WebInspect), and SCA, reducing false-positive noise from ~30% (300/1000 noisy findings) to near-zero.
- Team Leadership & Mentorship: Managed and mentored a team of 14 Application Security engineers, driving delivery excellence and automated verification frameworks.
- Conference Speaker: Presented "Smart Automation using Artificial Intelligence" at NULLCON 2025, sharing frameworks for using AI to eliminate repetitive security workflows.
βββββββββββββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β DOMAIN β TECHNOLOGIES & ARSENAL β
βββββββββββββββββββββββββββββββββΌββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Incident Response & PSIRT β Incident Triage, TruffleHog, CVE Analysis, Post-Mortems β
β Application Security β SAST, DAST, SCA, Threat Modeling, Architecture Review β
β Offensive Testing β Burp Suite Pro, Web/API Pentesting, Exploit Reproduction β
β Enterprise Security Tools β Fortify SSC/SCA, WebInspect, Checkmarx, Snyk, Prisma Cloudβ
β AI Security Automation β Claude AI Skills, Agentic Testing, Scanner Orchestration β
β Cloud & DevSecOps β Docker, OpenShift, Linux, GitHub Actions, Strict CSP β
β Programming Languages β Python, Java, TypeScript, JavaScript, SQL, Shell / Bash β
β Frameworks & Web Platforms β Next.js, React, Node.js, REST APIs, PostgreSQL, Redis β
βββββββββββββββββββββββββββββββββ΄ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
| Project | Description | Tech Stack |
|---|---|---|
| Clinkz | Autonomous penetration testing platform exploring agent loops, tool orchestration, CVE correlation, and evidence-driven reporting. | Python Docker LLM Security Automation |
| Burp to Fortify Parser | Bridge between Burp Suite exports and Fortify-aligned review workflows for automated finding translation and cleaner intake. | Python Burp Suite Fortify AppSec |
| Burp Fortify SSC Plugin | Enterprise Java plugin for ingesting and normalizing Burp Suite findings directly into Fortify SSC pipelines with preserved evidence. | Java Burp Suite Fortify SSC DAST |
| Invoker | AI-assisted vulnerability scanning & triage framework focused on high-confidence signal discovery and automated reachability analysis. | Python AI Security Vulnerability Triage |
| nyx | Local file intelligence and SHA-256 fingerprinting tool for defensible data auditing and duplicate detection. | TypeScript File Intelligence Automation |
- NULLCON 2025 (Goa, India): Speaker on "Smart Automation using Artificial Intelligence" β Exploring practical AI agent workflows to automate reconnaissance, finding correlation, and verification.



