security engineering

AppSec, security reviews, DevSecOps and zero-trust architecture. Threat models that name the attacker, controls that survive an audit.

  • appsec
  • devsecops
  • zero trust
  • threat modeling

Security as an engineering property, not a checklist bought at the end.

Scope: threat modeling, application security reviews, pipeline hardening, secrets and identity architecture, and executive security plans written in language a board can act on.

[ start a project ]