Updated October 2026
Now
What I'm working on this month. Application Security Engineer in Charleston, SC, with 5+ years of software engineering behind me.
Working on
- Passed GIAC GCIH (SEC504) in August 2026. The labs are published here: live PowerShell investigation, RITA beacon detection, Hayabusa log triage, and Nmap discovery.
- PortSwigger BSCP prep. Web pentesting is a skill I keep sharp, not my identity.
- Building llm-audit. Twelve OWASP LLM Top 10 rules shipped, more coming for the TS/JS ecosystem Semgrep's official AI pack does not cover.
- Studying for AWS Security Specialty (SCS-C03, target Q1 2027). IAM least-privilege, CloudTrail detection, and Cognito hardening against enumeration.
Certifications
| GIAC GCIH (SEC504) | Passed | Aug 2026 |
| GIAC GSEC | Passed | Apr 2026 |
| GIAC GFACT | Passed | Jan 2026 |
| AWS Security Specialty (SCS-C03) | In progress | Target Q1 2027 |
| PortSwigger BSCP | In progress | Target Q4 2026 |
| TryHackMe AI Security (AI1) | Planned | Late 2026 |
| HackTheBox AI Red Teamer path | Planned | 2027 |
| TCM PWPA (Web Pentest) | Planned | 2027 |
Open to
Senior Application Security, Senior Product Security, and AI Security roles. Remote. I reply within 24 hours to recruiters and hiring managers.