I help engineering teams turn security requirements into practical architecture. As a Security Architect with a background in software engineering and technical leadership, I define standards, patterns and controls that teams can apply throughout delivery.
My hands-on experience with applications, APIs, microservices and CI/CD allows me to connect business risk with clear technical decisions. I am open to selected international remote contracts and security architecture engagements.
Standards, reusable patterns and controls that turn risk requirements into clear design decisions.
Quality gates, SAST, DAST and dependency controls integrated into CI/CD workflows.
Cloud and platform guardrails based on least privilege, Zero Trust and defense in depth.
Architecture reviews and practical guidance for applications, APIs and distributed systems.
Defining security standards, governance processes, reusable security patterns and architectural controls.
Embedding Security by Design into architecture and software delivery practices.
Supporting the implementation of an enterprise Security Architecture domain.
Represented a four-person engineering team and contributed to a microservices architecture.
Identified, documented and helped remediate more than 100 vulnerabilities and associated CVEs.
Applied OWASP Top 10, Zero Trust and clean architecture principles while improving delivery from 12 user stories to more than 78 features.
Led six developers and owned application architecture in a large energy-sector environment.
Introduced CI/CD quality and security controls including SonarCloud, SAST and DAST.
Recovered delivery from four months behind schedule to two weeks early and increased development throughput by 114%.
Modernized legacy systems, designed APIs and improved database and application performance.
Delivered secure custom software and e-commerce products, including a Next.js and Stripe platform that received more than 20,000 visits in its first week.
Security architecture, governance, DevSecOps, application security, cloud security, resilience and offensive security.
Full stack software engineering, databases, deployment and web application development.
Professional certification in cybersecurity and cloud security.
Professional certification in cloud security governance.
Leadership development for complex business and technical environments.