I build security tools that close the gap between detection and action.
5 tools shipped Β· autonomous HTB pipeline Β· 2.4M domains blocked Β· zero cloud APIs.
Cyber Security Analyst at lululemon, Vancouver BC β spanning SIEM operations, cloud security, penetration testing, and security tooling development.
Daily work: Splunk, IBM QRadar, ELK Stack, AWS GuardDuty, Azure Sentinel. IAM/PAM with Okta and Active Directory. Offensive tooling β Nmap, Metasploit, Burp Suite.
Outside of work: 5 shipped security tools in Python, a self-hosted homelab running Wazuh, Greenbone, and a full vulnerability management pipeline β and an autonomous HTB pentest agent that handles recon through exploitation without human input.
TryHackMe top 1%. 10+ TCM Security certifications. Target: OSCP 2028, Staff Security Engineer shortly after.
Each one solves a real security problem. Built in Python, runs on-prem, open source.
Deduplicates Semgrep/Bandit/ZAP findings by CWE+location, scores risk 0β10, LLM false-positive filter, SARIF 2.1.0 export for GitHub Code Scanning.
STRIDE analysis across all components. MITRE ATT&CK + OWASP + NIST mapping. Auto-flags GDPR/PCI-DSS violations. On-prem LLM narratives. Executive HTML report with Chart.js visuals.
Parses auth.log + journalctl JSON, detects 7 attack patterns mapped to MITRE ATT&CK with confidence scoring. AbuseIPDB enrichment, email alerts, local LLM assessment.
Autonomous vulnerability discovery inspired by DARPA AIxCC. AFL++ fuzzing β ASan/GDB triage β LLM root cause (CWE) β patch generation β recompile + validate. Pluggable LLM: Ollama, Claude, OpenAI.
Autonomous HTB/CTF pentest agent: recon β enum β web β exploit β report. Parallel tool execution β nikto+gobuster, enum4linux+ldap+snmp run simultaneously. Human-in-the-loop checkpoints. LLM-guided at every stage.
HackTheBox and TryHackMe machine writeups with custom exploit scripts. Commit-on-root discipline: every rooted machine β writeup β push.
Hands-on C exploitation β stack overflows, heap corruption, UAF. GDB + pwndbg analysis. Foundation for OSCP exploit development track.
A real self-hosted infra stack β not a tutorial VM. Used daily for security practice, tool development, monitoring, and offensive lab work.
Technical writeups on tools I build, machines I root, and concepts I'm learning. Published on dev.to.
// loading posts...
Open to Senior / Staff Security Engineer roles β Vancouver or remote. I bring production tooling, a working offensive lab, and real detection engineering experience. Not looking for recruiters, looking for engineers.