Portfolio#
Every project here has a public repository behind it, so you can check the claims against the code.
- Speaking — a recorded Syxsense Master Class, plus the Black Hat USA booth stage, hands-on customer workshops, and a week-long university seminar in India.
- Running a POC — how I scope, run, and close a technical evaluation, including the vendor security review that stalls most enterprise security deals.
- Security — a local NIST NVD mirror in PostgreSQL, so vulnerability data can be joined against a real asset inventory instead of queried through someone else’s UI.
- GitOps — this site: Hugo content and the Terraform that runs it in one repository, shipping itself to S3 and CloudFront through GitHub Actions for about a dollar a month.
- Automation — Jarvis, a plugin-based executive brief agent, plus a hard drive triage auditor and a Clonezilla image builder.
- AI Agents — a marketplace of Claude Code skills and read-only cloud plugins that front-load standards so an agent produces defensible output instead of improvising.
- X as Code — Terraform and Ansible labs: a Proxmox-backed Kubernetes cluster and a disposable RHCE study environment on DigitalOcean.
On compliance: the long-form version of what I know is the SOC 2 Field Manual for Seed Stage SaaS — controls by platform and budget, auditor selection, the compliance calendar, and an honest read on Drata, Vanta, Secureframe, and doing it in a spreadsheet.