About
Daniel Begimher builds, breaks, and benchmarks AI security systems.
I work across AI security, cloud security, application security, incident response, and developer-first security tooling.
Secure Steps with Begimher is where I publish practical field notes on how security systems are built, evaluated, broken, and improved in the real world.
I am currently at AWS, but this site is independent: the views and opinions expressed here are my own and do not necessarily reflect the positions or policies of my employer.
How I Got Here
A broad security background across architecture, incident response, cloud security, AppSec, and AI security.
I have spent more than a decade in security, and the through-line has stayed the same: turn hard security problems into systems that help people make better decisions.
I started in network and enterprise security, then moved through security architecture, incident response, red-team work, cloud security consulting, and security engineering. That background shaped how I think about AI security: useful systems need evidence, boundaries, clear failure modes, and a human path back to judgment.
At AWS, I led development of the company’s first customer-facing AI security agent and now work on red-team agents and end-to-end evaluation for AWS Continuum for code vulnerabilities. I also co-lead AWS’s global Application Security field community, connecting customer needs, field specialists, and service teams to improve AppSec guidance and programs at scale.
That is the lens behind my public work: SIR-Bench, Automated Security Helper (ASH), ThreatForest, and AI Leak Watch.
Public Work
A few public-safe proof points from AI security research, open source, and developer-first security tooling.
SIR-Bench
A benchmark for evaluating whether AI incident-response agents actually investigate, discover evidence, and use tools instead of summarizing alerts.
Automated Security Helper (ASH)
Developer-first security scanning for local and CI/CD workflows, with 200k+ monthly clones and 650+ GitHub stars.
ThreatForest
A multi-agent system for turning source repositories into TTP-mapped attack trees and evidence-based mitigations. Published on arXiv and selected for an upcoming Black Hat USA 2026 briefing.
AI Leak Watch
A public dashboard tracking potentially exposed AI provider keys and the way agentic workflows change secret-exposure blast radius.
Writing And Talks
Public writing and sessions on AI security, AppSec, cloud security, incident response, and developer workflows.
A control framework for AI coding agents
Author-time guardrails, build-time verification, and risk-based human review for AI-assisted development.
Conference talks
Sessions at AWS re:Invent, AWS re:Inforce, Cyber Week, and an upcoming Black Hat USA 2026 ThreatForest briefing.
Selected work
A broader index of public projects, publications, research, and talks across AI security, cloud security, AppSec, and incident response.
How To Reach Me
For public work, writing, and talks, these are the best starting points.
Connect and follow public updates.
GitHub
Open-source projects and research artifacts.
AWS Security Blog
Public AWS security writing and demos.