I'm a security engineer and architect in Seattle who likes building the thing, not just writing the requirement for it.
My background spans infrastructure, cloud platforms, identity, application security, automation, observability, and federal compliance. I've worked from Linux and network engineering through Azure and AWS architecture, spent time handling Severity-A cloud escalations at Microsoft, and have taken two organizations from Cybersecurity Maturity Model Certification (CMMC) gap assessment through successful certification.
A lot of my work sits where security architecture meets engineering: turning ambiguous requirements into systems, controls, automation, diagrams, and operating models that people can actually use.
This is also a relatively new GitHub for me. I recently retired an older account I'd had since 2016 that had accumulated a pretty random mix of projects over the years. This one is intentionally more focused on enterprise security, application security, cloud, identity, and security engineering.
The projects here explore things like governed coding agents, non-human identity, infrastructure as code, secure application design, policy enforcement, evidence, and the engineering practices behind security controls. I intentionally keep the design decisions, validation mechanisms, and occasional failures visible, not just the finished product.
Most of the larger projects connect through control-plane, while the smaller repositories are experiments, demonstrations, diagrams, and study material.
I build primarily with Python, Terraform, Bicep, PowerShell, cloud-native services, and whatever else is useful for making security repeatable.
If you like the program (control-plane) or the main application (manifest-identity), please give them a ⭐ and let me know!
| Project | What it does |
|---|---|
| manifest-identity | An application for reviewing who has access to what across an organization's cloud accounts and directories. It keeps a record, written by a named person, of what access each identity is allowed to have; it imports what seven providers report and shows every difference between the two records; it runs review campaigns that put each difference in front of the person responsible, one decision at a time. It never changes anything in the systems it reads. |
| build-doctrine | The rulebook the program's code is built under: standards for letting an AI coding agent write code a person is responsible for, where each rule names the problem behind it and the check that catches it. It provides a scorer that grades any repository from 0 to 5 on each rule, a vetting tool that reads a dependency before it is adopted, a project template with the checks switched on, and coverage of seven published security frameworks with the gaps listed. |
| control-plane | The platform the applications run on: an AWS estate defined as code, with every security choice explained beside the code that makes it. It will hold the organization and its accounts, a persistent foundation and an ephemeral workload rebuilt daily, identity without stored keys, the image promoted by digest, the cloud's own monitoring, and recovery drilled on a schedule. The plan is written; the code is next. |
| secure-expense-mvp | A deliberately small application that carries application security end to end: object-level authorization, bounded file handling, transactional audit records, dependency integrity, security-gated delivery, and tests proven by deliberately breaking the controls they protect. |
| Project | What it is |
|---|---|
| sample-diagrams | Architecture and process diagrams showing how I communicate systems, trust boundaries, data flows, operational workflows, and cross-team handoffs. |
| Project | What it is |
|---|---|
| aws-azure-security-mapping | Ninety-nine AWS security concepts mapped to their closest Azure counterparts, including the cases where the two platforms have no clean equivalent. |
| anki-decks | Seven maintained study decks, 1,262 cards across PowerShell, Python, KQL, Bicep, cybersecurity, the AWS Security Specialty, and compliance frameworks. Each deck also has a plain CSV source so changes can be reviewed in Git. |
Certifications
![]() CISSP |
Cybersecurity Architect Expert |
Azure Solutions Architect Expert |
Microsoft 365 Administrator Expert |
![]() Terraform Associate |
![]() CCNA |
Skills and tools
Cloud security. Azure, AWS, Microsoft 365, secure landing zones, network segmentation, private connectivity, cloud security architecture.
Identity and zero trust. Entra ID, Conditional Access, PIM, non-human identities, workload identities, managed identities, service principals, SAML, OIDC, OAuth 2.0.
Security engineering and automation. Terraform, Bicep, Python, PowerShell, KQL, policy as code, CI/CD security gates, secure-by-design engineering.
Detection and observability. Microsoft Sentinel, Splunk, Cribl, Defender, CloudTrail, GuardDuty, log pipelines, detection engineering, threat hunting.
Governance and compliance. CMMC, NIST 800-171, NIST 800-53, FedRAMP, CIS Benchmarks, architecture reviews, control implementation, continuous monitoring.
The projects here are meant to be inspected. Design decisions, rejected alternatives, tests, controls, and failures are kept visible so the implementation can be evaluated rather than simply trusted.








