Selected Work

Open-source tools, AI security research, publications, and talks.

A curated index of public-safe work across developer-first security tooling, AI security research, AWS and CSA publications, and conference sessions.

Production AI Security Systems

Public work across agent development, adversarial evaluation, and security-agent measurement.

Incident response agent

AWS Security Incident Response

Led development of AWS’s first customer-facing AI security agent, including evaluation methodology and synthetic incident environments for evidence-driven investigations.

Adversarial evaluation

AWS Continuum for code vulnerabilities

Built red-team agents and led end-to-end evaluation using synthetic, production-like applications across vulnerability discovery, exploit validation, remediation quality, safety, and regressions.

Field leadership

Application Security at AWS

Co-lead AWS’s global Application Security field community, connecting customer needs, field specialists, service teams, and security leadership through technical guidance and enablement.

Open source

Automated Security Helper

Developer-first security scanning for local and CI/CD workflows. Current headline metric: 200k+ monthly clones.

AI security research

AI Leak Watch

A public dashboard that tracks potentially exposed AI provider keys on GitHub and explains why secret leakage gets more serious in agentic systems.

Publications

AWS Security Blog

Security articles and demos on AI-powered investigations, CodeBuild defense-in-depth, and practical cloud security.

Publications

Selected public writing and framework contributions.

Talks

Selected sessions and demos.

2025

AWS re:Invent: From Code to Cloud

Building AppSec programs with AWS and agentic AI for AppSec.

2025

AWS re:Inforce: Improve Code Quality with Amazon Q Developer

AI-assisted security across the SDLC.