01
The short version
I'm a CISSP security and infrastructure engineer who helps startups build
security that holds up in the real world: cloud architecture, identity, compliance,
automation, and the unglamorous glue between them.
For the last several years, I've often been the one-person security team
at fast-growing companies, wearing every hat from compliance owner to AWS infrastructure
engineer. I've led SOC 2 Type II and ISO 27001 programs
from scratch while staying hands-on with Terraform, EKS, IAM, Okta, and Zero Trust access.
My bias is practical: security should make the safe path easier, not slow the business
down. I still come at this as an engineer, which means I'd rather automate a control than
write a policy nobody reads, and I care about systems that engineers will actually keep using
after the audit is over.