Security telemetry and SIEM
Getting the right logs into the right place, cheaply, with detections that hold up. Log source onboarding for CrowdStrike Next-Gen SIEM, Panther, Google SecOps, and Elastic. Cloudflare Logpush and Qualys integrations. Cribl and vector.dev pipelines to cut ingest cost. MITRE ATT&CK coverage mapping. Diagnosed Elastic shard exhaustion on a live university cluster and drove the fix.
Observability for AI agents
Author of claude-otel, an open-source OpenTelemetry collection and SIEM export pipeline for Claude Code sessions: prompts, tool calls, token and cost totals, session-level JSONL to S3 with KMS and short-lived Vault credentials. A customer chose it over their SIEM vendor's native option. Also: OTel collector configuration, Jaeger tracing, Datadog ingest cost tuning.
Identity and directory
Okta Universal Directory, group rules, and HR-driven provisioning. Rewrote a pharmacy benefits manager's Workday-to-Okta model: composite department attributes and about 239 dual-value group rules so access stayed stable through cutover. Reconciled an 8,000-field environment delta down to the 47 objects that mattered. Active Directory forest migration work, including WinRM remediation on domain controllers. Google Workspace to Okta migration tooling with zero-impact password import.
Cloud landing zones and compliance
Authored a multi-phase AWS Control Tower plan for an internal landing zone built as a reusable harness: Security Hub, Audit Manager, SCP rationalization, IAM Identity Center, vendor log control plane, and a 49-row preflight checklist with an evidence bundle. Drata SOC 2 readiness audit. GitHub Actions to AWS with OIDC instead of static keys. GCP for the AI side: Cloud Run, Pub/Sub, BigQuery, Vertex AI, VPC peering.
Application and supply chain security
Rolled StepSecurity harden-runner from audit to enforcement across a monorepo and satellite repos, with egress allowlists and proof-of-blockage. Ran an LLM-assisted, engineer-reviewed, second-model-verified code security assessment across two repositories, then restaged it after 100-plus remediation commits with stable finding IDs. Cloudflare WAF and application security review with a read-only API collector.
Data engineering
Five years of pipelines before security. Pipeline SME for a mobile platform with a global user base: Airflow on Cloud Composer, BigQuery, Postgres Cloud SQL, GA4 and CRM ingestion, Dataplex standardization. Earlier: ETL/ELT for large technology and financial services companies and federal agencies, and warehouse work in MSSQL, MySQL, and MariaDB. M&A sensitive-data discovery that took 47,318 candidates down to 214 documented exceptions.
Agentic AI systems
Built an AI alert-triage pipeline on GCP: Panther alerts to a Cloud Run RAG agent to BigQuery to Tines, with Vertex AI Vector Search replacing SQL similarity for a 100x query speedup at a third of the cost. Built a self-hosted agentic assistant (Tauri desktop, multi-agent plans, review gates, multi-provider LLM). Running a research program on model-agnostic harness design with pre-registered predicates across Grok, Claude, Gemma, and Qwen.
Delivery and leadership
Lead architect across six concurrent enterprise engagements. Author of milestone-based fixed-fee SOWs, assessment reports in technical and leadership tiers, and M&A due-diligence deliverables. Manage engineers and contractors, run hiring, own customer architecture calls with CISO-level sponsors. I take the blame and pass on the credit.