I build security tools that close the gap between detection and action.
5 tools shipped Β· autonomous HTB pipeline Β· 2.4M domains blocked Β· zero cloud APIs.
Cyber Security Engineer at lululemon, Vancouver BC β building automation that closes the gap between vulnerability discovery and remediation.
When I joined, vulnerability management was entirely manual β check Wiz, MDE, Qualys, and Recorded Future by hand, find asset owners, cut tickets one by one. Days of work per CVE cycle. I built an AWS Lambda pipeline that automated ownership mapping, correlated findings across all four tools, and routed tickets automatically to the right teams. Mean time from CVE identification to ticket dropped from days to under 30 minutes. After integrating AI-driven contextualization against the CISA KEV catalog, that became seconds β with severity normalized to our actual environment, not raw CVSS.
Outside of work: 5 shipped security tools in Python, a self-hosted homelab running Wazuh, Greenbone, and a full vulnerability management pipeline β and an autonomous HTB pentest agent that handles recon through exploitation without human input.
TryHackMe top 1%. 10+ TCM Security certifications. Target: OSCP 2028, Staff Security Engineer shortly after.
Each one solves a real security problem. Built in Python, runs on-prem, open source.
Deduplicates Semgrep/Bandit/ZAP findings by CWE+location, scores risk 0β10, LLM false-positive filter, SARIF 2.1.0 export for GitHub Code Scanning.
STRIDE analysis across all components. MITRE ATT&CK + OWASP + NIST mapping. Auto-flags GDPR/PCI-DSS violations. On-prem LLM narratives. Executive HTML report with Chart.js visuals.
Parses auth.log + journalctl JSON, detects 7 attack patterns mapped to MITRE ATT&CK with confidence scoring. AbuseIPDB enrichment, email alerts, local LLM assessment.
Autonomous vulnerability discovery inspired by DARPA AIxCC. AFL++ fuzzing β ASan/GDB triage β LLM root cause (CWE) β patch generation β recompile + validate. Pluggable LLM: Ollama, Claude, OpenAI.
Autonomous HTB/CTF pentest agent: recon β enum β web β exploit β report. Parallel tool execution β nikto+gobuster, enum4linux+ldap+snmp run simultaneously. Human-in-the-loop checkpoints. LLM-guided at every stage.
HackTheBox and TryHackMe machine writeups with custom exploit scripts. Commit-on-root discipline: every rooted machine β writeup β push.
Hands-on C exploitation β stack overflows, heap corruption, UAF. GDB + pwndbg analysis. Foundation for OSCP exploit development track.
A real self-hosted infra stack β not a tutorial VM. Used daily for security practice, tool development, monitoring, and offensive lab work.
Technical writeups on tools I build, machines I root, and concepts I'm learning. Published on dev.to.
/var/log/auth.log is full of signal. Brute forces, privilege escalations, new user accounts β all there. But finding them β¦
Run Semgrep and Bandit on the same Python repo and you’ll get the same SQLi finding at app.py:42 β¦
Archetype β HTB Starting Point, Windows machine.
IP: 10.10.10.27
nmap -sV -sC -p- 10.10.10.27
Interesting ports:
445/tcp β¦Open to Senior / Staff Security Engineer roles β Vancouver or remote. I bring production tooling, a working offensive lab, and real detection engineering experience. Not looking for recruiters, looking for engineers.