↓ Skip to main content

About

I build security products. I spent years breaking them first.

I lead the technical side of security R&D at Cyshield and own the security architecture across what we build: an AI-native ASPM platform, agentic SOC systems, and a commercially launched AI-powered WAF.

The platform finds vulnerabilities in customer code without that code leaving the customer’s environment. The SOC systems let agents carry the routine investigation work while analysts stay accountable for disposition. The WAF sits inline on all customer traffic, which makes its own security a first-order concern rather than an afterthought.

What connects them
#

Defensibility. Every security decision eventually has to be justified to a customer, an auditor, or a board. So findings carry their history from one scan to the next, and every step an agent takes is recorded where a person can review it, challenge it, or overturn it. That is the difference between AI that makes a team faster and AI that makes a team liable.

Evaluation and cost
#

I also run our evaluation and benchmarking practice, which is what keeps AI claims honest. Before we tell anyone an AI-assisted approach beats what it replaced, we measure it against known answers and record what we find, including the results that went against the design I had most invested in.

Most of that depends on the model layer, so a fair amount of my time goes into deploying and tuning open-weight models on vLLM and llama.cpp behind OpenAI-compatible gateways, and building the harnesses that let one security core run against a local or a hosted model. Cost gets measured alongside recall rather than after the fact. The sequence matters: make it work, prove it does what it claims, then make it affordable to run at scale.

Before this
#

Security consulting and offensive assessment for enterprise clients in banking, telecom and fintech, finding by hand the vulnerabilities I now build tooling to scan for. Web application and network penetration testing end to end, manual secure code review as a core service line, and enterprise DevSecOps at Unifonic between 2024 and 2025.

First place at the EG-CERT national CTF, published CVEs (CVE-2017-1000058, CVE-2018-5222), and vulnerability research disclosed to Twitter, Sony, Adobe, Ford, Pinterest and Dell. I’m also the creator of DVBLab, a deliberately vulnerable banking application used for secure code review training.

Certifications
#

OSAI, OSWE, eWPTXv2, eCPPTv2, eMAPT, CDP, CCSE and CCNSE. Every one is listed with a working verification link on the certificates page.

Contact
#

There are no articles to list here yet.