Security Engineer, San Jose CA

Securing the Cloud, the Model,
and Everything in Between.

Security engineer specializing in AI security, cloud infrastructure and IAM, offensive security, and DevSecOps. Led an organization-wide cloud posture audit, establishing least-privilege IAM, network segmentation, and a zero-egress perimeter. Hardened self-hosted vLLM serving against prompt injection and trojaned releases, and built an autonomous offensive-security engine that sandboxes an abliterated open-weights model. OSCP certified with deep expertise in STRIDE threat modeling, shipping robust solutions in Rust, Golang, Python, Kubernetes, and Terraform.

01

Expertise

01

Offensive Security

Internal and external penetration testing across web, cloud, Active Directory, and Kubernetes. Attack-path analysis, exploit development, and an autonomous offensive-security engine that sandboxes an abliterated open-weights model.

  • Pentesting
  • Attack-Path Analysis
  • Exploit Dev
  • MITRE ATT&CK
  • EASM
02

AI Security

Securing the LLM stack end to end. Hardened self-hosted vLLM serving against prompt injection and trojaned model releases, isolated agent tool servers, and threat-model AI systems with MITRE ATLAS.

  • Prompt-Injection Defense
  • Model Supply Chain
  • MCP Isolation
  • MITRE ATLAS
  • vLLM Hardening
03

Cloud Infrastructure & IAM

Led an organization-wide cloud posture audit and hardened the estate: least-privilege IAM, network segmentation, VPC Service Controls, deny-by-default egress, and a zero-egress serving perimeter.

  • CNAPP / CSPM
  • Least-Priv IAM
  • VPC Service Controls
  • Zero-Egress
  • GCP / AWS / Azure
04

DevSecOps

Detection engineering, container and Kubernetes hardening, and CI/CD security. Built agentic vulnerability triage grounded in deterministic controls, with STRIDE threat modeling across the SDLC.

  • Kubernetes / Docker
  • Detection Engineering
  • STRIDE
  • Trivy
  • Elastic SIEM
02

Selected Work

Platform security engineering at a stealth startup, plus internal and external red-team work. Details generalized to respect confidentiality.

Autonomous Offensive-Security Engine

Security AI

Built an AI system that runs authorized penetration engagements behind a human approval gate, grounding every technique in a security-knowledge corpus and sandboxing an abliterated open-weights model so it can never reach the network or identity it runs on.

  • Pydantic AI
  • Hybrid RAG
  • gVisor Sandbox
  • MITRE ATT&CK
  • GKE

Cloud Posture Audit & Hardening

Cloud Security

Ran an organization-wide posture audit across the cloud estate and drove remediation end to end: least-privilege IAM, network segmentation, VPC Service Controls, and deny-by-default egress, materially raising CIS benchmark compliance.

  • CNAPP / CSPM
  • Least-Priv IAM
  • VPC-SC
  • Prowler
  • Terraform

Self-Hosted LLM Serving Hardening

AI Infrastructure

Locked down self-hosted vLLM serving with per-client RBAC and a strict zero-egress perimeter, then defended the prompt path and model supply chain, blocking a trojaned release and isolating agent tool servers.

  • vLLM
  • RBAC
  • Zero-Egress
  • MCP Isolation
  • Linkerd mTLS

Agentic Vulnerability Triage

DevSecOps

Authored a deterministic-first triage pipeline that enriches scanner findings with threat intelligence, scores exploitability against a compensating-control graph, and automates ticket lifecycle and SLAs across thousands of findings.

  • Python
  • Threat Intel
  • EPSS / KEV
  • Exploitability Scoring
  • Automation
03

Open Source

Selected public tooling. Full source and more on GitHub.

04

Technologies

Offensive Security

  • Web / DB Pentesting
  • Cloud & Container Pentesting
  • Active Directory
  • Kubernetes
  • Attack-Path Analysis & Chaining
  • Exploit Development
  • EASM
  • MITRE ATT&CK & ATLAS

Cloud & IAM

  • GCP
  • AWS
  • Azure
  • CNAPP / CSPM
  • Least-Privilege IAM
  • Workload Identity
  • VPC Service Controls
  • Deny-by-Default Egress
  • Bucket Hardening (UBLA)
  • IAP
  • Prowler

AI & LLM Security

  • vLLM Serving
  • FP8 Quantization
  • Prompt-Injection Defense
  • Model Supply Chain
  • MCP Isolation
  • Guardrails AI
  • Hybrid RAG
  • Qdrant
  • Pydantic AI
  • LangGraph
  • LLM Red Teaming

Languages & Data

  • Rust
  • Golang
  • Python
  • PowerShell
  • Bash
  • PHP
  • SQL
  • JavaScript
  • Neo4j / Cypher
  • Redis / Valkey
  • Kafka
  • ClickHouse
  • Elasticsearch
  • MongoDB

Infrastructure & DevSecOps

  • Kubernetes
  • Terraform
  • Helm
  • Docker
  • Pod Security
  • NetworkPolicy
  • Trivy
  • Detection Engineering
  • Elastic SIEM
  • Incident Response
  • Linux Hardening
  • n8n

Frameworks & Compliance

  • NIST CSF
  • NIST RMF
  • NIST 800-53
  • ISO 27001
  • SSDF
  • CIS Benchmarks
  • STRIDE
  • C4 Architecture
05

Research

Graduate Research, Boston University, April 2025

Securing Web-Based Database Applications

A study of broken access control and security misconfiguration in web-based database applications, walking through live attack demonstrations, impact analysis, and defense-in-depth mitigations grounded in least privilege and secure deployment.

Read the paper (PDF)
06

Hack The Box

At Pro Hacker rank, I work hands-on across web, Active Directory, cloud, and privilege-escalation paths. I also captain a competitive CTF team and led Boston University's NCAE CyberGames team to a regional win at the 2025 East Overflow and a fourth-place finish among twelve teams, earning Most Valuable Teammate honors at both the invitational and the regional.

Rank Pro Hacker
Role Team Captain
07

Certifications & Education

Certifications

  • OSCPOffensive Security Certified Professional
  • CompTIA Security+Core Security Skills
  • AZ-900Microsoft Azure Fundamentals
  • Splunk Search ExpertSPL and Detection
  • GCP Professional Cloud Network EngineerIn ProgressGoogle Cloud networking and security

Education

  • M.S. CybersecurityBoston University, GPA 3.94, 2024-2026

Recognition

  • NCAE CyberGamesTeam Captain, 2025 East Overflow Regional Winner
  • Most Valuable TeammateInvitational & Regional
  • PresidentBU MET CyberSec Club
08

Get In Touch