I build secure cloud platforms, automate delivery, and explore better ways to protect modern infrastructure.
I work where cloud engineering, backend automation, and security meet. My focus is designing infrastructure and delivery systems that are secure by default, observable in production, and straightforward for teams to operate.
I enjoy turning security controls into repeatable engineering workflows: policy as code, hardened Kubernetes platforms, supply-chain checks, GitOps delivery, and useful automation in Python and Go.
My engineering bias: automate the guardrails, keep the platform observable, and make the secure path the easiest path.
| Area | Focus |
|---|---|
| Cloud & platforms | AWS, Azure, GCP, Kubernetes, Docker, Helm, Talos Linux |
| Security engineering | Container security, IAM/RBAC, secrets, vulnerability management, policy as code |
| Delivery & infrastructure | Terraform, Ansible, GitHub Actions, GitOps, Argo CD, CI/CD architecture |
| Backend & automation | Python, Go, APIs, event-driven workflows, operational tooling |
| Reliability | Prometheus, Grafana, logging, incident response, resilience and cost awareness |
My current engineering lab explores practical questions around cloud-native defense and platform reliability:
- Kubernetes hardening — testing secure-by-default cluster patterns, RBAC boundaries, admission controls, and CIS-aligned configurations.
- Software supply-chain security — exploring image provenance, dependency and IaC scanning, SBOMs, signing, and policy enforcement in CI/CD.
- AI-assisted cloud security — experimenting with agents that turn cluster signals and misconfigurations into useful, explainable remediation guidance.
- GitOps safety — investigating how policy gates, drift detection, and progressive delivery can reduce operational risk without slowing teams down.
- Runtime visibility — learning how eBPF and cloud-native telemetry can improve threat detection and incident investigation.
These are active experiments and evolving notes—not finished research claims. I share useful implementations as they become ready.
A hands-on platform lab for deploying and operating a Talos Kubernetes cluster with infrastructure as code, networking, storage, observability, and GitOps workflows.
A Python automation service that turns job discovery into a focused personal digest—an experiment in practical workflow automation and useful signal extraction.
A TypeScript product demo for an AI-assisted job-search experience, connecting backend automation with a clear user-facing workflow.
My fork and experimentation space for an AI-powered Kubernetes security agent, focused on understanding cluster risk and actionable remediation.
I am interested in cloud security, platform engineering, Kubernetes, DevSecOps, and open-source security tooling. If you are working on something in that space, connect with me on LinkedIn or send me an email.



