I help early-stage startups and engineering teams solve security problems when they need security expertise but don't need a full-time security team.
Practical security support for specific projects, assessments, POCs, implementations, and security gaps.
Security engineering support for startups and engineering teams that need practical help without building a full-time security team.
Review and improve the security of your AWS environment, from architecture and IAM to logging, detection, and encryption.
Help secure Docker and Kubernetes environments across the development pipeline and runtime.
Assess and strengthen AI applications against common LLM-specific threats and abuse cases.
Areas I explore through writing, research, and hands-on projects.
PostQ is a tool for discovering and inventorying cryptographic assets across a network, including TLS/HTTPS endpoints, SSH services, and email infrastructure.
It focuses on evaluating these assets from a post-quantum risk perspective, helping identify:
The goal is to move beyond simple scanning and provide a policy-driven risk assessment layer for post-quantum readiness.
Interested in one of my services? Feel free to connect with me.