Selected Work
Open-source tools, AI security research, publications, and talks.
A curated index of public-safe work across developer-first security tooling, AI security research, AWS and CSA publications, and conference sessions.
Production AI Security Systems
Public work across agent development, adversarial evaluation, and security-agent measurement.
AWS Security Incident Response
Led development of AWS’s first customer-facing AI security agent, including evaluation methodology and synthetic incident environments for evidence-driven investigations.
AWS Continuum for code vulnerabilities
Built red-team agents and led end-to-end evaluation using synthetic, production-like applications across vulnerability discovery, exploit validation, remediation quality, safety, and regressions.
Application Security at AWS
Co-lead AWS’s global Application Security field community, connecting customer needs, field specialists, service teams, and security leadership through technical guidance and enablement.
Automated Security Helper
Developer-first security scanning for local and CI/CD workflows. Current headline metric: 200k+ monthly clones.
AI Leak Watch
A public dashboard that tracks potentially exposed AI provider keys on GitHub and explains why secret leakage gets more serious in agentic systems.
AWS Security Blog
Security articles and demos on AI-powered investigations, CodeBuild defense-in-depth, and practical cloud security.
Publications
Selected public writing and framework contributions.
Cloud Security for Startups 2024
Cloud Security Alliance whitepaper.
Understanding Cloud Attack Vectors
Cloud Security Alliance publication.
AWS Well-Architected Security Pillar
Application Security section contribution.
Talks
Selected sessions and demos.
AWS re:Invent: From Code to Cloud
Building AppSec programs with AWS and agentic AI for AppSec.
AWS re:Inforce: Improve Code Quality with Amazon Q Developer
AI-assisted security across the SDLC.
Mitigating OWASP Top 10 CI/CD Security Risks
AWS re:Invent 2024 session slides.
Common Threat Actor Tactics
Cyber Week 2024 talk observed by AWS CIRT.