I'm a cybersecurity leader with over a decade of experience building resilient security programs across financial services, government, and tech sectors. Currently, I'm a Staff Security Engineer at PIP Labs, where I bridge traditional enterprise security with the emerging challenges of Web3 and blockchain infrastructure.
My career has taken me from Amazon to Zapier, with hands-on experience leading penetration testing engagements at HackerOne and architecting cloud security at scale. I specialize in appsec, cloud architecture (AWS, GCP, Azure), threat modeling, and secure DevOps practices. Whether it's implementing comprehensive CSPM solutions, leading red team exercises, or mentoring engineering teams on secure development, I focus on security that enables business innovation.
On Medium, I share insights on practical security strategies, lessons learned from real-world assessments, emerging threats in cloud and Web3 environments, and how to build security programs that actually work. I'm passionate about demystifying complex security concepts and helping teams build more secure systems.
When I'm not hunting vulnerabilities or fine-tuning security automation, you'll find me contributing to bug bounty programs, mentoring the next generation of security professionals, and staying ahead of the threat landscape through continuous research.
Let's connect if you're interested in application security, cloud infrastructure, or navigating the unique security challenges of Web3.
