Case Studies
The problems, decisions, and operating models behind my work in product security.
Open-source tooling
SecOps Dashboard
Built a self-hosted workflow for importing, investigating, and triaging security findings. Explore the product and try a sample workflow.
Read case studyProduct security
Building Product Security from Scratch
Established AppSec, cloud security, vulnerability management, and governance as the first dedicated security engineer at Licious.
Read case studyDevSecOps
Security in the Delivery Pipeline
Integrated Semgrep and Trivy into CI/CD, tuned findings, and introduced enforcement based on confidence and risk.
Read case studySecurity product
Building CyberShield360
Built an attack surface management product at Invia, from asset discovery and enrichment to prioritization and reporting.
Read case studyCloud security
Hardening AWS Cloud Posture
Connected CSPM findings to IAM, network, and data access controls, then validated changes through traffic and logs.
Read case studyDetection engineering
Validating WAF Coverage
Compared AWS WAF coverage with OWASP CRS categories and evaluated proposed rules in count mode before enforcement.
Read case studyCloud security
Prioritizing AWS Attack Paths
Evaluated how exposure, permissions, and trust relationships could combine, then sequenced remediation by business impact.
Read case studyDeveloper tooling
Security Feedback Before Commit
Added local checks for secrets, IaC configuration, and common code patterns, backed by independent CI enforcement.
Read case studySecurity operations
Operating a Bug Bounty Program
Defined scope, triage criteria, ownership, and remediation workflows to turn external reports into engineering action.
Read case studyGovernance
Making ISO 27001 Readiness Operational
Mapped controls to accountable teams and repeatable evidence workflows across Engineering, IT, HR, and Finance.
Read case study