For Employers
Hands-on platform and product engineering
I bring a blend of software engineering, DevSecOps, and software supply chain thinking shaped by both homelab experimentation and real product work.
Hire
I work best where secure delivery, developer tooling, and practical infrastructure design all matter at the same time.
For Employers
I bring a blend of software engineering, DevSecOps, and software supply chain thinking shaped by both homelab experimentation and real product work.
For Clients
SBOM generation and analysis, dependency vulnerability triage, artifact signing setup, and practical remediation priorities.
CI/CD pipelines with Syft, Grype, and Cosign integrated into hosted or self-managed infrastructure.
Support for teams navigating OSS risk, license awareness, contributor trust, and security-conscious contribution workflows.
Introductory or intermediate sessions on software supply chain security for developer communities, teams, and internal engineering groups.
Evidence of Work
The blog documents how I think about SBOMs, artifact signing, self-hosted CI, and zero-trust networking. That writing is the best public record of the standards I try to bring into engineering work.