Fractional Security Engineering

Helping you build secure systems.

I help early-stage startups and engineering teams solve security problems when they need security expertise but don't need a full-time security team.

AWS Cloud Security Container Security AI / LLM Security Security Engineering
๐Ÿ›ก๏ธ

On-Demand Security Engineering

Practical security support for specific projects, assessments, POCs, implementations, and security gaps.

โ˜๏ธ AWS Security Reviews & Hardening
๐Ÿณ Kubernetes & Runtime Security
๐Ÿค– LLM Red Teaming & Guardrails
โš™๏ธ Security Automation & POCs

๐Ÿ›ก๏ธ What I Can Help You With

Security engineering support for startups and engineering teams that need practical help without building a full-time security team.

โ˜๏ธ

AWS Cloud Security

Review and improve the security of your AWS environment, from architecture and IAM to logging, detection, and encryption.

  • AWS security architecture reviews
  • IAM & least privilege
  • KMS & encryption
  • CloudTrail, GuardDuty & Config
  • Security hardening
  • Security POCs & implementation
๐Ÿณ

Container Security

Help secure Docker and Kubernetes environments across the development pipeline and runtime.

  • Docker & Kubernetes security
  • Runtime security
  • DevSecOps
  • Container vulnerability management
  • RBAC & network security
  • Supply-chain security
๐Ÿค–

AI / LLM Security

Assess and strengthen AI applications against common LLM-specific threats and abuse cases.

  • LLM security assessments
  • LLM red teaming
  • Prompt injection testing
  • RAG security
  • AI security architecture
  • Guardrails & mitigations
What Else I Offer Security Automations (Python & Bash) Suricata IDS / IPS Security tooling integration Security POCs

๐Ÿ“ Blog

Recent Posts

๐Ÿงญ Topics

Areas I explore through writing, research, and hands-on projects.

๐Ÿงช Featured Project

๐Ÿ” PostQ โ€” Post-Quantum Risk Assessment Tool

PostQ is a tool for discovering and inventorying cryptographic assets across a network, including TLS/HTTPS endpoints, SSH services, and email infrastructure.

It focuses on evaluating these assets from a post-quantum risk perspective, helping identify:

  • Quantum-vulnerable cryptographic algorithms
  • Weak or outdated configurations
  • Overall cryptographic exposure across systems

The goal is to move beyond simple scanning and provide a policy-driven risk assessment layer for post-quantum readiness.

Not just discovery โ€” but understanding cryptographic risk in a post-quantum world.

๐Ÿ“ฌ Connect

Interested in one of my services? Feel free to connect with me.