I am a security engineer and architect in Seattle, working in cloud and identity security for regulated and federal environments. I have taken two organizations from gap assessment through Cybersecurity Maturity Model Certification. Most of the repositories below form control-plane, a security engineering program built in public with a governed coding agent: every change agent-proposed, human-reviewed, signed, and gated, with the decisions and the failure record kept on purpose. The diagrams repository stands on its own.
| Repository | Details |
|---|---|
| control-plane | The program the repositories form: phases fixed before building, monitoring and recovery documented with drills that expire, and the agent governed by gates it cannot route around. |
| role-call | Inventory and governance for non-human identities, the roles, service accounts, and access keys nobody offboards. State derives from observed history rather than being stored, and the tool amplifies a human decision rather than acting on its own. Complete through its version one scope. |
| build-guidelines | The standards every project here starts from, organized by layer. Each rule names what enforces it and the incident that produced it; what no tool can check is named as a human attestation with an expiry. |
| Repository | Details |
|---|---|
| secure-expense-mvp | A small expense application, finished and hardened: object-level authorization, tokenized values, audit logging, a security-gated pipeline. Complete on purpose. |
| sample-diagrams | Hand-drawn architecture and process diagrams, drawn in Visio, kept as illustration-only examples of design work |
CISSP · Terraform Associate · CCNA · Microsoft Expert x3

