// background
Security research shaped by operations.
I study security boundaries where software trusts input, identity, code, or another system more than it should.
01 / the path
Why boundaries come first.
My research now spans several connected areas: AI infrastructure, robotics and distributed systems, IoT and embedded devices, industrial software, and security-sensitive open-source infrastructure.
The common thread is not a particular product category. It is the trust boundary.
I study what happens when one component accepts commands, data, identity, code, network destinations, certificates, firmware, or state from another component and the assumptions behind that trust fail.
That same methodology applies to an AI model server, a robotics control plane, an IoT management application, an industrial device, or a cloud-connected edge service.
Security research is my current work. The route here ran through operations, enterprise infrastructure, incident response, detection engineering, and environments where every control needs evidence.
My work starts with source and a threat model. I trace data to the security decision, reproduce the behavior in a controlled environment, test the strongest objection, and separate an odd implementation detail from an exploitable boundary failure.
Automation and AI accelerate source review, triage, and hypothesis generation. They do not replace controlled reproduction, matched controls, or evidence.
Detection engineering, cloud security, incident response, enterprise infrastructure, and compliance-sensitive work remain part of the foundation. They are context for the research, not the headline.
IoT and industrial systems are an increasing part of this work. These environments combine software, devices, networks, management tools, remote services, and physical operations. Security failures can therefore exist between layers rather than inside a single application. My research looks at those interfaces: device management, firmware behavior, network services, authentication, authorization, certificate validation, update mechanisms, protocol handling, and communication between devices, gateways, edge systems, and cloud services.
My industrial security research includes two publicly disclosed Lantronix G520 vulnerabilities, credited in CISA ICS Advisory ICSA-26-272-01 and addressed by the vendor.
02 / experience
A direct line from operations to research.
- 2026 - present
Independent Security Researcher
Source-led vulnerability research across AI infrastructure, robotics, IoT, embedded devices, industrial systems, and open-source infrastructure. Work includes architecture review, source analysis, protocol and firmware analysis, reproducible testing, exploit validation, matched controls, coordinated disclosure, patch review, and remediation verification.
- 2025 - present
Security and Compliance Consultant
Application and infrastructure assessments across cloud, identity, endpoint, and control surfaces. Findings are translated into prioritized engineering work and tracked through remediation.
- 2022 - 2025
Computer Security Manager
Enterprise hardening, segmentation, access review, investigation, endpoint and server security, and incident-response work.
- Earlier career
Business ownership and operations
Vendor, operational-risk, scheduling, and service-delivery ownership across a distributed logistics operation.