I've secured browser extensions, Google Workspace applications, enterprise endpoints, and API gateways at Flashpoint, completing 70+ application assessments and reviewing 100+ third-party vendors. I automated extension analysis with Python and Semgrep, administered Cloudflare WAF, and implemented Prisma SASE DLP policies to reduce application and data-exfiltration risk.
I'm currently researching software supply chain risks through self-hosted Forgejo Actions, OpenSSF Scorecard, Syft, Grype, and SLSA controls. Previously, I built self-healing Tripwire automation at Mastercard, reduced manual remediation by 50%, and engineered Chef and Jenkins migrations supporting zero-touch deployments across thousands of agents.
