ConsultingWorkbench-backed AI security engagements — map, attack, defend, and prove your AI systems.
Scope a Review

Engagement Portfolio

Capability proof for AI security engineering.

Public-safe examples showing the kinds of systems, evidence, reviews, research, and operating models behind our consulting practice.

Browse signals

Projects

66

Companies

37

Featured

3

Claim ready

2

Use the proof buckets below to move from broad capability to concrete case study quickly.

33 records use company imagery

Browse capability proof

Filter by capability, proof status, and delivery context.

Public-safe examples are grouped by the capability they prove for AI Security Engineering: governance evidence, product security, detection, research synthesis, enterprise delivery, and adjacent origins.

Engagement type

All projects

Projects

66

Companies

37

Featured

3

Company imagery

33

Public-safe

2

Visible now

66

Showing 66 of 66 public-safe examples. Filters preserve the curated proof order, so the strongest AI security capability signals stay visible first.

Featured proof

Pinned project anchors

The most public-facing proof remains pinned even when the rest of the directory is filtered.

The State of AI Security Engineering Report 2026 portrait cover
AI Security LLC2026
Public-safe with caveat

The State of AI Security Engineering Report 2026

A flagship research report turning AI security job-market noise into evidence about roles, skills, control gaps, hiring signals, and the emerging AI security engineering discipline.

Designed and authored a flagship 2026 research report on AI security engineering, using a corpus of AI and security job descriptions, role analysis…

Proves: governance evidence
AI Security EngineeringAI Security ReportLabor Market ResearchCybersecurity Hiring

Consultants

AI Security LLC
Open project
The AI Security Engineering Field Guide portrait cover
aisecurity.llc2026
Public-safe with caveat

The AI Security Engineering Field Guide

A compact, action-oriented field guide for AI security engineering practitioners working in fast-moving environments.

The AI Security Engineering Field Guide is a compact, action-oriented companion for practitioners who need direct guidance — not long-form referenc…

Proves: governance evidence
AI SecurityField GuidePractitioner ToolsRapid Reference

Consultants

aisecurity.llc
Open project
AI Product Security in the Age of Mythos — book cover
AI Security LLC2026
Buyer-ready proof

AI Product Security in the Age of Mythos

A practical AI product-security framework for agentic systems, governance evidence, excessive agency, RAG authorization, and continuous threat modeling.

Created a flagship AI product-security framework explaining how agentic AI changes the product-security operating model: inventory becomes the firs…

Proves: governance evidence
AI Product SecurityAgentic AI SecurityProduct SecurityApplication Security

Consultants

AI Security LLC
Open project

AI Security & Governance Proof

Public-safe proof of AI security assessments, operating models, governance evidence, and buyer-facing claim support.

16 projects
The AI Security Engineer's Handbook portrait cover
AI Security LLC2026
Buyer-ready proof

The AI Security Engineer's Handbook

A practical field handbook for turning AI security from policy language into executable engineering work, control evidence, and operator-ready workflows.

Created a practitioner-oriented AI Security Engineering Handbook that translates AI risk, governance, product-security, and agentic-system concerns…

Proves: governance evidence
AI Security EngineeringAI Product SecurityProduct SecurityApplication Security

Consultants

AI Security LLC
Open project
AI Product Security Control Plane hero image
Consulting
Confidential AI-Native Product Team2025–2026
Public-safe with caveat

AI Product Security Control Plane

A compact methodology for connecting AI inventory, threat modeling, prompt injection, agent permissions, RAG authorization, AI supply chain, evidence, and governance.

Framed AI product security as a product-control problem and translated AI risk categories into evidence, backlog, and governance language that prod…

Proves: governance evidence
AI Product SecurityControl PlaneThreat ModelingPrompt Injection

Consultants

Confidential AI-Native Product Team
Open project
AI Security Operating Model hero image
Advisory
Confidential AI Governance Program2025–2026
Public-safe with caveat

AI Security Operating Model

A lightweight operating model for turning AI governance into ownership, evidence, controls, and delivery decisions.

Designed a practical AI security operating model that connects governance to evidence, ownership, and engineering decisions instead of leaving it a…

Proves: governance evidence
AI GovernanceOperating ModelSecurity OwnershipEvidence

Consultants

Confidential AI Governance Program
Open project
Enterprise Product Security Program Buildout hero image
Confidential Enterprise Software Environment2025–2026
Public-safe with caveat

Enterprise Product Security Program Buildout

A program-buildout case study focused on making product security measurable, fundable, and useful to engineering and customer conversations.

Helped build and operate product-security program foundations so the work became measurable, fundable, and useful to engineering and enterprise cus…

Proves: governance evidence
Product SecurityProgram BuildoutEvidenceSecurity Posture

Consultants

Confidential Enterprise Software Environment
Open project
Browser-Native Trust Boundary Security Model portfolio cover
Consulting
Confidential Browser Security Research2025–2026
Public-safe with caveat

Browser-Native Trust Boundary Security Model

A product-security research model for browser-native applications, extension bridges, native sidecars, privileged pages, postMessage flows, host-object exposure, persistence, credential surfaces, and governed automation boundaries.

Developed a browser-native trust-boundary security model from deep assessment work on desktop browser architectures, privileged internal pages, nat…

Proves: search, retrieval, and data quality
Browser SecurityTrust BoundariesProduct SecurityWebView

Consultants

Confidential Browser Security Research
Open project
B2B API Repository Security & Refactoring Automation portfolio cover
Confidential Consulting ProjectCirca 2012
Internal/private

B2B API Repository Security & Refactoring Automation

A pre-Splunk consulting project applying SAST, DAST, linting, secrets extraction, AST transforms, automated refactoring, and genetic-programming research across hundreds of GitHub-hosted B2B API repositories.

Conducted a consulting and research project focused on large-scale analysis and automated refactoring of GitHub-hosted B2B API repositories, includ…

Proves: detection / incident readiness
B2B APIsGitHub Repository AnalysisSASTDAST

Consultants

Confidential Consulting Project
Open project
Mandiant — Operation Aurora DFIR & FBI Cybercrime Training hero image
Consulting
Mandiant (Google Cloud)2009–2011
Public-safe with caveat

Mandiant — Operation Aurora DFIR & FBI Cybercrime Training

DFIR response to Operation Aurora at Adobe and Google; criminal attribution for FBI wanted financial fraud cases; FBI cybercrime academy instruction.

Principal consultant at Mandiant during one of the most consequential periods in enterprise security history — deployed on Operation Aurora DFIR ef…

Proves: detection / incident readiness
DFIRIncident ResponseOperation AuroraNation-State Threats

Consultants

Mandiant (Google Cloud)
Open project
Disney IAM SIEM Alert Debugging & Executive Dashboard hero image
Consulting
DisneyCareer Role
Public-safe with caveat

Disney IAM SIEM Alert Debugging & Executive Dashboard

A Splunk-based IAM monitoring and executive reporting project across Disney access-control and identity systems for campuses and offices.

Delivered Splunk-focused IAM and SIEM work for Disney, debugging identity and access-control alerts, building a custom Splunk app, and creating exe…

Proves: governance evidence
DisneySplunkSIEMIAM

Consultants

UNUM LLM Attack Story & Detection Engineering hero image
Consulting
UNUM2024–2025
Public-safe with caveat

UNUM LLM Attack Story & Detection Engineering

A paid consulting engagement using LLM-assisted attack trees, MITRE ATT&CK mapping, ServiceNow asset inventory, enterprise architecture context, synthetic logs, and Splunk SPL detections.

Delivered a two-month consulting engagement for UNUM that used LLM-assisted attack-tree and attack-story generation, MITRE ATT&CK mapping, ServiceN…

Proves: governance evidence
UNUMAI SecurityDetection EngineeringLLM Attack Stories

Consultants

Hotel Marketers Hospitality Booking Intelligence & GIS Inventory Normalization hero image
Consulting
Hospitality marketing and booking infrastructure2005
Internal/private

Hotel Marketers Hospitality Booking Intelligence & GIS Inventory Normalization

Technical hospitality marketing, destination data, inventory normalization, and direct-booking support for independent hotels.

Reconstructed from 2005-era Hotel Marketers site copy, this case study captures technical hospitality work focused on direct-booking enablement, de…

Proves: search, retrieval, and data quality
Hotel MarketersHospitalityTravelInformation Science

Consultants

Hospitality marketing and booking infrastructure
Open project
Caya logo — Forex PCI DSS Level 3 Compliance portfolio cover
Consulting
Forex trading platform2010
Internal/private

Caya Forex PCI DSS Level 3 Compliance

PCI DSS Level 3 scoping, gap analysis, and compliance program delivery for a forex trading and payment processing platform.

Delivered a PCI DSS Level 3 compliance engagement for Caya, a forex trading and payment processing platform. Work covered scoping, cardholder data…

Proves: search, retrieval, and data quality
CayaForexPCI DSSLevel 3

Consultants

Forex trading platform
Open project
Trada logo — Data.com B2B Rainmaker Contact Intelligence portfolio cover
Consulting
Performance advertising platform2011
Internal/private

Trada — Data.com B2B Sales Contact Intelligence & ABM Rainmaker

3x Salesforce Data.com Rainmaker recognition for OSINT-driven B2B contact mining, normalization, and ABM outreach campaign delivery for a performance advertising platform.

Delivered B2B contact intelligence, OSINT-driven contact mining, and ABM outreach campaign execution for Trada, a performance advertising platform.…

Proves: search, retrieval, and data quality
TradaData.comSalesforceRainmaker

Consultants

Performance advertising platform
Open project
Cogstate logo — Regulated Health Data Product Delivery portfolio cover
Consulting
Cogstate2012
Internal/private

Cogstate Cognitive Measurement Delivery for the Australian Defence Force

Clinical and cognitive-assessment technology delivery for Australian Defence Force-linked workflows, emphasizing data integrity, privacy, workflow reliability, evidence, and customer trust.

Contributed to technology delivery in a Cogstate engagement on behalf of the Australian Defence Force, where cognitive-assessment and regulated hea…

Proves: governance evidence
CogstateAustralian Defence ForceHealth TechnologyClinical Research

Consultants

Cogstate
Open project
Pathwwway logo — iGaming Deputy Head of Technology portfolio cover
Pathwwway iGaming2017
Internal/private

Pathwwway iGaming Deputy Head of Technology

Technology leadership for an iGaming platform, spanning delivery ownership, platform operations, engineering coordination, regulated gaming constraints, data workflows, and security-aware execution.

Served in a Deputy Head of Technology capacity for a Pathwwway iGaming engagement before Forescout, helping guide technology delivery, platform ope…

Proves: governance evidence
PathwwwayiGamingDeputy Head of TechnologyTechnology Leadership

Consultants

Pathwwway iGaming
Open project
Pathwwway logo — ISO 27001 Audit & Management Consulting portfolio cover
Consulting
Pathwwway iGaming2017
Internal/private

Pathwwway ISO 27001 Audit & Management Consulting

ISO 27001 information security management system audit, gap analysis, and management consulting for a regulated iGaming platform.

Delivered ISO 27001 information security management system (ISMS) audit and management consulting for Pathwwway, a regulated iGaming platform. Work…

Proves: governance evidence
PathwwwayISO 27001ISMSAudit

Consultants

Pathwwway iGaming
Open project
NIST NICE Cyber Workforce Research Program hero image
Consulting
Sapient Search Group2024–2026
Public-safe with caveat

NIST NICE Cyber Workforce Research Program

A cyber-workforce research program featured at RSA Conference, bSides NYC, and Infosecurity Europe, translated into a talent-intelligence and ATS workflow layer.

Developed a NIST NICE Cyber Workforce research program focused on role language, workforce taxonomy, and cyber-workforce signal extraction, then tr…

Proves: search, retrieval, and data quality
NIST NICE Cyber WorkforceSapient Search GroupAI RecruitingATS Platform

Consultants

Sapient Search Group
Open project

Product Security & AppSec Proof

Architecture reviews, trust-boundary work, secure SDLC, application security, and product risk reduction.

22 projects
MYTHOS: The AI Security Narrative portrait cover
aisecurity.llc2026
Public-safe with caveat

MYTHOS: The AI Security Narrative

A book about the stories that shape how people think, build, and govern AI security.

MYTHOS examines the dominant narratives — the myths, metaphors, and mental models — that shape how security teams, executives, and builders approac…

Proves: governance evidence
AI SecurityNarrativeGovernanceSecurity Leadership

Consultants

aisecurity.llc
Open project
Internet Rising documentary portfolio cover
Culture Case
Internet Rising2011–2012
Canonical Team Source With Public Context

Internet Rising

A feature-length documentary exploring the internet, collective consciousness, digital culture, creators, and the social meaning of networked life.

Created a feature-length interview documentary exploring how the internet was reshaping creativity, identity, culture, consciousness, media, entrep…

Proves: search, retrieval, and data quality
Internet CultureDocumentary FilmDigital ConsciousnessCreator Economy

Consultants

Internet Rising
Open project
Glowing Plant Project synthetic biology portfolio cover
Culture Case
Glowing Plant Project2013
Canonical Team Source With Public Context

Glowing Plant Project

Synthetic biology research and public imagination around engineered living systems, bio-design, crowdfunding, regulation, and the boundaries of technological possibility.

Contributed research lineage and scientific context that became part of the Glowing Plant Project, a prominent synthetic-biology effort that brough…

Proves: governance evidence
Synthetic BiologyBioengineeringGlowing Plant ProjectEmerging Technology

Consultants

Glowing Plant Project
Open project
The Entrepreneur's Journey portfolio cover
Culture Case
Riverbanks2024
Public Claim

The Entrepreneur's Journey

A book, audiobook, and program translating entrepreneurial growth into a structured journey from inspiration to global impact.

Created The Entrepreneur's Journey as a book, audiobook, and program for helping founders and operators move from inspiration toward global impact…

Proves: enterprise delivery
EntrepreneurshipExecutive JourneyRiverbanksBusiness Development

Consultants

Riverbanks
Open project
Tales from the Animal Arcana portfolio cover
Culture Case
Tales from the Animal Arcana2025–2026
Canonical Team Source

Tales from the Animal Arcana

A multilingual collection of 78 animal-based fairy tales and fables, each paired with a tarot-inspired illustrated card and written for modern moral complexity.

Produced Tales from the Animal Arcana, a beautiful multilingual ebook collection of 78 animal-based fairy tales and fables. Each tale is paired wit…

Proves: system mapping and evidence packaging
Tales from the Animal ArcanaFablesFairy TalesAnimal Archetypes

Consultants

Tales from the Animal Arcana
Open project
AI Governance Controls portfolio cover
Confidential AI Governance Program2025–2026
Public-safe with caveat

AI Governance Controls with Garak, NeMo Guardrails, Presidio & Promptfoo

Implementing practical AI control evidence for ISO 42001, NIST AI RMF, AIMS, agent identities, permissions, red teaming, privacy, and output evaluation.

Designed a practical AI governance control layer using Garak, NeMo Guardrails, Microsoft Presidio, Promptfoo, agentic identities, permission scopin…

Proves: governance evidence
AI GovernanceAI Product SecurityISO 42001NIST AI RMF

Consultants

Confidential AI Governance Program
Open project
Agentic Workflow Migration and DSL Automation Platform portfolio cover
Confidential AI Automation Program2025–2026
Public-safe with caveat

Agentic Workflow Migration & DSL Automation Platform

Migrating brittle AI automation experiments into governed, Git-based, containerized agent workflows with schemas, verification, scoring, and acceptance gates.

Designed and implemented a migration path from brittle n8n and AutoGPT-style automations toward more governable Flowise and Sim Studio workflows, b…

Proves: product security and trust boundaries
Agentic WorkflowsAI AutomationWorkflow MigrationDSL Design

Consultants

Confidential AI Automation Program
Open project
Browser-Native Agentic AI Security Control Plane portfolio cover
Confidential AI Automation Platform2025–2026
Public-safe with caveat

Browser-Native Agentic AI Security Control Plane

A product-security architecture for governing browser extensions, Tauri sidecars, MITM interception, local AI, schema normalization, agent authority, and audit-ready automation.

Designed a browser-native AI security control plane connecting Chrome extension automation, persistent offscreen workers, WebLLM, Transformers, Rus…

Proves: governance evidence
AI Product SecurityBrowser-Native AIAgentic AI SecurityChrome Extension

Consultants

Confidential AI Automation Platform
Open project
Chrome Extension WebLLM, WASM & Automation Runtime portfolio cover
Confidential AI Automation Platform2025–2026
Public-safe with caveat

Chrome Extension WebLLM, WASM & Automation Runtime

A browser-extension AI runtime embedding WebLLM, Transformers, persistent offscreen workers, WASM engines, Puppeteer-core automation, MITM-style interception, schema normalization, and WSS listeners.

Designed and implemented a Chrome extension runtime for AI-assisted browser automation, embedding WebLLM and Transformers models, persistent offscr…

Proves: search, retrieval, and data quality
Chrome ExtensionBrowser AutomationWebLLMTransformers

Consultants

Confidential AI Automation Platform
Open project
Chrome Extension WebLLM, WASM & Puppeteer Automation Platform project cover
Internal Product2023–2026
Public-safe with caveat

Chrome Extension WebLLM, WASM & Puppeteer Automation Platform

A browser-native AI automation platform embedding WebLLM, WASM modules, Puppeteer-core-style automation, page injections, tool registries, request capture, and authenticated-context workflows.

Built a browser-native AI automation platform using a Chrome extension with embedded WebLLM, smaller local models, WASM modules, tool registries, p…

Proves: search, retrieval, and data quality
Chrome ExtensionBrowser-Native AIWebLLMWASM

Consultants

Internal Product
Open project
Rust/WASM Supabase AI Security Engine Platform portfolio cover
Internal Product2025–2026
Public-safe with caveat

Rust/WASM Supabase AI Security Engine Platform

A WASM-first AI/security backend architecture using Rust engines, Supabase Edge Functions, PostgREST, canonical schemas, scoring engines, extraction pipelines, and evidence-ready APIs.

Designed and implemented a Rust/WASM-first backend architecture for AI security, job intelligence, fit scoring, schema extraction, prioritization,…

Proves: governance evidence
RustWASMSupabaseEdge Functions

Consultants

Internal Product
Open project
Schema-Driven AI Workspace & Newtab Platform portfolio cover
Internal Product2025–2026
Public-safe with caveat

Schema-Driven AI Workspace & Newtab Platform

A browser-native AI workspace using schema-rendered panels, Preact/React UI surfaces, data-driven tool registries, Chrome extension newtab/sidepanel UX, and low-bloat local-first product design.

Designed and implemented a schema-driven AI workspace across Chrome extension newtab and sidepanel surfaces, using a pure-data panel registry, conf…

Proves: search, retrieval, and data quality
Schema-Driven UIAI WorkspaceChrome ExtensionNewtab

Consultants

Internal Product
Open project
GitOps Multi-Agent SDLC Automation Platform portfolio cover
Internal Product2025–2026
Public-safe with caveat

GitOps Multi-Agent SDLC Automation Platform

A Git-backed agentic software delivery system using workflow graphs, code remediation agents, evaluator agents, acceptance criteria, audit trails, issue linkage, and AI-assisted engineering controls.

Designed and implemented a GitOps-oriented multi-agent SDLC automation platform where AI agents analyze repositories, propose fixes, remediate bugs…

Proves: governance evidence
GitOpsMulti-Agent SDLCAgentic Software EngineeringBug Remediation

Consultants

Internal Product
Open project
GitHub Repository Intelligence & Security Automation portfolio cover
Independent Research & Internal Platform2012–2026
Public-safe with caveat

GitHub Repository Intelligence & Security Automation

Repository-mining and code-intelligence work applying static analysis, secrets detection, AST parsing, schema extraction, dependency review, and automated remediation patterns across developer ecosystems.

Built a long-running repository-intelligence practice around GitHub-hosted code: mining API repos, identifying insecure examples, extracting secret…

Proves: detection / incident readiness
GitHubRepository IntelligenceSecurity AutomationStatic Analysis

Consultants

Independent Research & Internal Platform
Open project
ATS Job Intelligence & Automation Platform portfolio cover
Internal Product2025–2026
Public-safe with caveat

ATS Job Intelligence & Automation Platform

A browser, desktop, and web platform for harvesting ATS jobs, normalizing job data, scoring fit, tracking applications, and automating career workflows across Greenhouse, Lever, Ashby, Workable, and related systems.

Designed and built an AI-powered job intelligence and career automation platform spanning Chrome extension, Tauri desktop app, Next.js web app, Sup…

Proves: search, retrieval, and data quality
ATS IntelligenceJob IntelligenceCareer AutomationRecruiting Intelligence

Consultants

Internal Product
Open project
Piper AI SDR & Hyper-Personalized Outreach Platform portfolio cover
Internal Product2024–2026
Public-safe with caveat

Piper AI SDR & Hyper-Personalized Outreach Platform

A Sales AI platform combining personality intelligence, email discovery, CRM enrichment, LinkedIn context, cold outbound automation, and agentic sales workflows.

Designed and built Piper, an AI-powered SDR and hyper-personalized outreach platform combining personality intelligence, lead enrichment, email dis…

Proves: system mapping and evidence packaging
PiperAI SDRSales AIOutbound Automation

Consultants

Internal Product
Open project
Browser-Native Contact Intelligence & Email Discovery Engine project cover
Internal Product2023–2026
Public-safe with caveat

Browser-Native Contact Intelligence & Email Discovery Engine

A Hunter.io-style contact intelligence platform using browser-local lookup, company/domain mining, Tranco-scale datasets, H1B/public data, GitHub/arXiv signals, LinkedIn URL discovery, and email-pattern prediction.

Built a browser-native contact intelligence and email discovery engine designed to compete with Hunter.io, ContactOut, Skrapp, RocketReach, Apollo-…

Proves: search, retrieval, and data quality
Contact IntelligenceEmail DiscoveryHunter.io AlternativeBrowser-Native Lookup

Consultants

Internal Product
Open project
Psychographic Job Fit & Recruiting Intelligence Engine portfolio cover
Internal Product2024–2026
Public-safe with caveat

Psychographic Job Fit & Recruiting Intelligence Engine

A fit-scoring and recruiting-intelligence system modeling role fit, team fit, culture fit, company fit, psychographic fit, nearest-neighbor similarity, and explainable candidate-job matching.

Designed and built a psychographic job-fit and recruiting-intelligence engine that models job fit, role fit, team fit, culture fit, company fit, an…

Proves: system mapping and evidence packaging
Psychographic FitJob FitRole FitTeam Fit

Consultants

Internal Product
Open project
CORE Behavioral Interview Intelligence Platform project cover
RiverBanks / Internal Product2023–2026
Public-safe with caveat

CORE Behavioral Interview Intelligence Platform

A behavioral interview and self-discovery platform built from 6,000+ interview questions, 30,000 company analyses, STAR scoring, NLP clustering, LLM judges, and iterative coaching loops.

Built CORE as a behavioral interview intelligence and career self-discovery platform around the dimensions Character, Objectives, Relationships, an…

Proves: system mapping and evidence packaging
COREBehavioral InterviewingCareer CoachingSTAR Scoring

Consultants

RiverBanks / Internal Product
Open project
Sovereign AI Mattermost Agentic Services Platform portfolio cover
Confidential Consulting Client2025–2026
Public-safe with caveat

Sovereign AI Mattermost Agentic Services Platform

A private AI collaboration stack combining Mattermost, a custom MFE app, Ollama, LocalAI, GitLab service workflows, model benchmarking, audit trails, and ISO 42001 / OWASP-aligned agentic delivery controls.

Designed and deployed a sovereign AI collaboration and agentic services platform using Mattermost, a custom micro-frontend Mattermost app, Ollama,…

Proves: governance evidence
Sovereign AIMattermostCustom MFEGitLab

Consultants

Confidential Consulting Client
Open project
Tauri Rust MITM Sidecar & Schema Normalization Engine portfolio cover
Confidential AI Automation Platform2025–2026
Public-safe with caveat

Tauri Rust MITM Sidecar & Schema Normalization Engine

A macOS-first Rust/Tauri sidecar with MITM proxying, 164 schema normalizers/adapters, streaming WSS processing, and LLM chat interception pipelines.

Designed and implemented a Rust-based Tauri desktop sidecar with MITM proxy capabilities, request/response interception, streaming WebSocket proces…

Proves: search, retrieval, and data quality
TauriRustMITM ProxySchema Normalization

Consultants

Confidential AI Automation Platform
Open project
Tauri Rust AI Sidecar, Apple Bridge & Capability Mesh project cover
Internal Product2023–2026
Public-safe with caveat

Tauri Rust AI Sidecar, Apple Bridge & Capability Mesh

A native AI sidecar architecture using Tauri, Rust, MITM proxying, WebSocket bridges, 160+ adapters, Apple-native APIs, VPN/network capabilities, and a dynamic capability mesh across devices and clients.

Designed and built a native AI sidecar platform using Tauri and Rust, combining MITM proxying, WebSocket pub/sub bridges, 160+ schema normalizers/a…

Proves: product security and trust boundaries
TauriRustNative AI SidecarMITM

Consultants

Internal Product
Open project

Research & Publications

Research, review, and proof artifacts that translate technical work into reusable evidence.

14 projects
DuckDuckGo Browser Security Assessment hero image
DuckDuckGo2026
Public-safe with caveat

DuckDuckGo Browser Security Assessment

A product-security assessment of browser trust boundaries, privileged page handling, native bridge exposure, and persistence pathways.

Conducted a deep product-security assessment of DuckDuckGo desktop browser architecture, focusing on WebView2 trust boundaries, duck:// privileged…

Proves: product security and trust boundaries
Product SecurityBrowser SecurityDesktop SecurityWebView2

Consultants

DuckDuckGo
Open project
AI Security Job Market Dataset & Analytics Engine portfolio cover
Internal Research2025–2026
Public-safe with caveat

AI Security Job Market Dataset & Analytics Engine

A labor-market intelligence engine analyzing AI security, product security, AppSec, governance, and emerging agentic-system roles across thousands of ATS job descriptions.

Built a job-market analytics engine for AI security engineering using thousands of ATS job descriptions, role taxonomies, skill extraction, securit…

Proves: governance evidence
AI SecurityJob Market AnalyticsLabor Market IntelligenceState of AI Security Engineering

Consultants

Internal Research
Open project
Agentic Browser Security Assessment hero image
Confidential AI Automation Platform2025–2026
Public-safe with caveat

Agentic Browser Security Assessment

A product-security assessment of browser trust boundaries, privileged pages, native bridges, persistence pathways, and agentic automation authority.

Developed a public-safe assessment model for agentic browser workflows that connect web content, browser extensions, native bridges, credentials, a…

Proves: search, retrieval, and data quality
Browser SecurityTrust BoundariesProduct SecurityBrowser Extensions

Consultants

Confidential AI Automation Platform
Open project
EMPOWER LIWC Psychometric Framework Factory project cover
RiverBanks / Internal Product2023–2026
Public-safe with caveat

EMPOWER LIWC Psychometric Framework Factory

A psychometric product engine combining LIWC-compatible text analysis, 300+ dictionaries, WASM/Go/Rust runtimes, personality prediction, survey frameworks, LMS packaging, and LLM-generated coaching reports.

Built EMPOWER as a psychometric framework factory and personality-intelligence engine, combining LIWC-compatible dictionary analysis, 300+ lexical…

Proves: research synthesis
EMPOWERPsychometricsLIWCWASM

Consultants

RiverBanks / Internal Product
Open project
Forescout Device Cloud Elastic/Kibana Analytics Platform hero image
Forescout2019–2020
Public-safe with caveat

Forescout Device Cloud Elastic/Kibana Analytics Platform

Large-scale connected-device analytics using Forescout Device Cloud, Elastic, Kibana, and security-research workflows to turn millions of device records into report-ready security evidence.

Built and executed Elastic/Kibana-style analytics workflows over Forescout Device Cloud data to support security research, sector-specific report f…

Proves: governance evidence
ForescoutDevice CloudElasticKibana
Forescout
Open project
Forescout Connected Medical Device Security Report hero image
Forescout2019–2021
Public-safe with caveat

Forescout Connected Medical Device Security Report

Device Cloud research on connected medical-device segmentation, insecure protocols, default credentials, legacy systems, and clinical-network exposure.

Contributed to Forescout connected medical-device research using Device Cloud analytics to examine segmentation failures, insecure protocols, defau…

Proves: search, retrieval, and data quality
ForescoutConnected Medical DevicesHealthcare SecurityIoMT
Forescout
Open project
Forescout Enterprise of Things Security Report 2020 hero image
Forescout2020
Public-safe with caveat

Forescout Enterprise of Things Security Report 2020

Device Cloud research identifying the riskiest IoT devices across financial services, government, healthcare, manufacturing, and retail.

Contributed to Forescout's Enterprise of Things Security Report research, using Device Cloud analytics and Elastic/Kibana-style workflows to help i…

Proves: search, retrieval, and data quality
ForescoutEnterprise of ThingsState of IoT Security 2020Device Cloud
Forescout
Open project
Forescout Banking on Security Financial Services Research hero image
Forescout2020
Public-safe with caveat

Forescout Banking on Security Financial Services Research

Device Cloud research on financial-services device risk, flat networks, IoT/OT proximity, POS exposure, Windows lifecycle risk, and segmentation gaps.

Contributed to Forescout's Banking on Security financial-services research, using Device Cloud analytics and Elastic/Kibana-style workflows to help…

Proves: search, retrieval, and data quality
ForescoutBanking on SecurityFinancial Services SecurityDevice Cloud
Forescout
Open project
Forescout Operational Technology Security Research hero image
Forescout2019–2020
Public-safe with caveat

Forescout Operational Technology Security Research

Device Cloud and research-backed analysis of OT, IoT, industrial, unmanaged, and cyber-physical systems as enterprise attack surfaces.

Contributed to Forescout operational-technology and Enterprise-of-Things research by using Device Cloud analytics and Elastic/Kibana-style workflow…

Proves: search, retrieval, and data quality
ForescoutOperational TechnologyOT SecurityIndustrial IoT
Forescout
Open project
Forescout DTEN / WIRED-Featured Offensive Security Research hero image
ForescoutCareer Role
Public-safe with caveat

Forescout DTEN / WIRED-Featured Offensive Security Research

Offensive security research into connected-device risk, enterprise exposure, and real-world exploitability, later featured in WIRED coverage.

Contributed to offensive security research involving DTEN and connected-device risk, helping expose how enterprise collaboration and IoT-style devi…

Proves: search, retrieval, and data quality
ForescoutDTENWIREDOffensive Security Research
Forescout
Open project
Devo Security Research & Conference Program hero image
Devo2022–2023
Public-safe with caveat

Devo Security Research & Conference Program

A public security research program turning SIEM deployment analysis, cloud detection patterns, architecture innovation, and SOC maturity findings into RSA, Infosecurity Europe, and CloudNativeSecurityCon-ready narratives.

Developed and contributed to Devo security research that converted customer deployment analysis, SIEM maturity patterns, detection taxonomy work, c…

Proves: detection / incident readiness
DevoSecurity ResearchConference ResearchRSA
Devo SIEM Reference Architecture, Taxonomy & Detection Validation hero image
Devo2022–2023
Public-safe with caveat

Devo SIEM Reference Architecture, Taxonomy & Detection Validation

Architecture innovation work redesigning SIEM reference architectures, standardizing detection taxonomy, validating Exchange content, and turning hundreds of enterprise deployments into maturity patterns.

Led and contributed to Devo architecture innovation work focused on SIEM reference architectures, detection taxonomy, Exchange-content validation,…

Proves: detection / incident readiness
DevoSIEMCloud SIEMReference Architecture

Consultants

Mapping Motives: Analysis of 2,000 Enterprise Cloud Detections hero image
Devo2023
Public-safe with caveat

Mapping Motives: Analysis of 2,000 Enterprise Cloud Detections

Linux Foundation / Cloud Native SecurityCon research on enterprise cloud detections, cloud SOC maturity, ATT&CK-aligned motives, and the growing importance of cloud-native telemetry in SIEM programs.

Presented Cloud Native SecurityCon North America 2023 research with Joshua Smith at Devo, analyzing 2,000 enterprise cloud detections to explain ho…

Proves: governance evidence
DevoCloudNativeSecurityConLinux FoundationCNCF
RiverBanks Workforce Development LMS Suite hero image
RiverBanks / Internal Product2023–2026
Public-safe with caveat

RiverBanks Workforce Development LMS Suite

A three-framework workforce-development product suite combining EMPOWER psychometrics, CORE interview intelligence, RISE self-authoring, SCORM/xAPI/LTI packaging, university pilots, and AI-generated coaching reports.

Designed and built a workforce-development LMS product suite around three major frameworks: EMPOWER for psychometrics and personality intelligence,…

Proves: research synthesis
RiverBanksWorkforce DevelopmentLMSEMPOWER

Consultants

RiverBanks / Internal Product
Open project

Enterprise Systems & Data Quality

Conservative public-safe summaries of prior enterprise delivery, data quality, search, retrieval, and system mapping work.

9 projects
Splunk Product Security Program Buildout hero image
Splunk2013–2014
Public-safe with caveat

Splunk Product Security Program Buildout

Building a scalable, evidence-driven product security function for a global enterprise software platform.

Partnered with Splunk to build and scale the product security program, strengthen secure development practices, and create the evidence, process, a…

Proves: governance evidence
Product SecuritySecure SDLCProgram BuildoutEnterprise SaaS
Splunkbase App Certification Program hero image
Splunk2015
Public-safe with caveat

Splunkbase App Certification Program

Turning a sprawling marketplace security problem into a repeatable app certification, review, and trust program.

Led the security architecture, verification, and delivery model behind Splunkbase App Certification, transforming inconsistent security review acro…

Proves: product security and trust boundaries
Product SecurityApplication SecurityMarketplace SecuritySecure SDLC

Consultants

Forescout Smart IoT Security Lab hero image
Forescout2016–2017
Public-safe with caveat

Forescout Smart IoT Security Lab

Established and directed a live Smart IoT Building security research lab spanning robotics, HVAC, ICS/SCADA, and SOC-style command center operations.

Built and directed Forescout's Smart IoT Building security research lab — a live, instrumented environment designed to surface real-world attack pa…

Proves: governance evidence
IoT SecurityICS/SCADAOT SecurityRobotics Security

Consultants

Forescout
Open project
Forescout Rapid Response Program hero image
Forescout2017–2018
Public-safe with caveat

Forescout Rapid Response Program

A security response operating model for urgent product, customer, vulnerability, and research-driven risk events in enterprise device-security environments.

Contributed to Forescout rapid response work by helping coordinate security research, product risk triage, technical validation, customer-impact an…

Proves: governance evidence
ForescoutRapid ResponseProduct SecuritySecurity Research
Forescout
Open project
ServiceNow Principal Security Research Program hero image
ServiceNow2022–2025
Public-safe with caveat

ServiceNow Principal Security Research Program

Advanced security research across ProdSec, AppSec, AI risk management, and AI voice threat modeling at enterprise SaaS scale.

Led advanced security research across product security, application security, and AI risk management at ServiceNow — one of the most widely deploye…

Proves: search, retrieval, and data quality
Security ResearchAI RiskProduct SecurityAppSec

Consultants

ServiceNow
Open project
Cornerstone FedRAMP Moderate ATO Security Controls hero image
Cornerstone OnDemand2015–2016
Public-safe with caveat

Cornerstone FedRAMP Moderate ATO Security Controls

A control-architecture and evidence-readiness effort translating FedRAMP Moderate requirements into policy, standards, technical controls, operational procedures, and audit-ready proof.

Supported Cornerstone's FedRAMP Moderate authorization effort by helping turn formal control requirements into security policies, standards, guidel…

Proves: governance evidence
Cornerstone OnDemandFedRAMPFedRAMP ModerateATO

Consultants

Cornerstone OnDemand
Open project
Syntryx OSINT Platform Product Buildout hero image
Syntryx2006–2010
Public-safe with caveat

Syntryx OSINT Platform Product Buildout

Leading product and engineering for a 2B-page open-source intelligence platform using high-throughput crawling, PostgreSQL-scale ingest, ML, NLP, clustering, search analytics, and graph visualization.

Led product and engineering for Syntryx, an open-source intelligence platform for multi-channel web and behavioral data, managing an 11-person team…

Proves: search, retrieval, and data quality
SyntryxOSINTOpen-Source IntelligenceProduct Leadership

Consultants

Cendant / Orbitz Affiliate Growth & ML Multileg Itinerary Generation hero image
Cendant / Orbitz2005
Internal/private

Cendant / Orbitz Affiliate Growth & ML Multileg Itinerary Generation

A technical marketing and machine-learning project generating high-value niche multileg flight itineraries to support affiliate growth, search demand capture, and travel-content expansion.

Supported affiliate-program growth and technical marketing by developing or contributing to machine-learning and data-driven methods for generating…

Proves: search, retrieval, and data quality
CendantOrbitzGTA Gullivers Travel AssociatesAffiliate Marketing

Consultants

Cendant / Orbitz
Open project
Cendant / Orbitz Geographic Waypoint & GDS Cleanup hero image
Cendant / Orbitz2006
Internal/private

Cendant / Orbitz Geographic Waypoint & GDS Cleanup

A travel-data quality project cleaning geographic waypoints, inventory metadata, and GDS-linked destination structures to improve search, booking, routing, and content reliability.

Contributed to geographic waypoint, destination inventory, and GDS cleanup work in a travel-technology environment, improving the structure, accura…

Proves: search, retrieval, and data quality
CendantOrbitzGTA Gullivers Travel AssociatesTravel Technology

Consultants

Cendant / Orbitz
Open project

Creative / Origins / Adjacent Work

Origins and adjacent public work that may explain range, but does not compete with current AI security positioning.

2 projects
The Mimicking Octopus portfolio cover
Culture Case
The Mimicking Octopus2024
Public Claim

The Mimicking Octopus

A maritime Southeast Asia research journey and book using the mimic octopus as a living metaphor for adaptation, identity, deception, and the search for true self.

Researched and wrote The Mimicking Octopus: A Journey to True Self, drawing on an exceptional maritime Southeast Asia journey to investigate the mi…

Proves: search, retrieval, and data quality
Mimic OctopusAnimal IntelligenceAdaptationIdentity

Consultants

The Mimicking Octopus
Open project
Lead With Purpose book portfolio cover
Culture Case
Lead With Purpose2025
Public-safe with caveat

Lead With Purpose

A 2025 leadership book by David Wolf that turns purpose, decision-making, and systems thinking into a practical operating frame for builders and operators.

Created Lead With Purpose as a public-safe leadership book by David Wolf, translating purpose, clear thinking, and systems-aware decision-making in…

Proves: system mapping and evidence packaging
LeadershipPurposeSystems ThinkingExecutive Education

Consultants

Lead With Purpose
Open project

Public-safe caveat

Projects use conservative public-safe language. They avoid raw job-description text, ATS payloads, personal data, secrets, private customer records, unapproved quotes, sponsor negotiation notes, unsupported maturity claims, accusatory company-level framing, and psychometric diagnosis.