I’m a security engineer in Denver. I build the data systems security teams depend on: intelligence pipelines, detection content, and the automation that connects them.
Right now I’m at DISH Network (EchoStar), building a threat intelligence platform and a threat research program from scratch — a production CTI platform in AWS, ingestion across fifty-odd open-source, dark web, and commercial sources, and the automation that pushes what comes out of it into blocking and detection. Alongside that, a retrieval system over the threat graph, and coverage for adversarial-AI threats: jailbreak and prompt-injection corpora normalised into STIX and mapped to MITRE ATLAS.
How I got here
I studied instrumentation and control engineering at NIT Trichy, which is not a security degree, and arrived at security through the operational end rather than the research end.
My first three years were at Wipro, on SIEM and SOC work: owning the technical workstream of a global SOC transition, migrating a 120TB QRadar deployment from on-premises to AWS, writing fifty-odd custom parsers, and modelling detection use cases against the log sources they fed. That period taught me the thing most of my writing comes back to — that the quality of a detection is capped by the quality of the pipeline underneath it, and the pipeline is where the unglamorous work lives.
Then a master’s in computer science at CU Boulder, and a stint building LLM-backed backend services, before moving into threat intelligence platform engineering.
How I work
Three things show up in everything on this site.
Decisions, not features. The project pages here are decision records: the problem, the choice made, the tradeoff accepted, and what it doesn’t do. A README that argues for a design decision is worth more than the code it describes.
Measured, not asserted. If I claim a number, it’s reproducible on public data. The evaluation of my own similarity digest leads with the result that argues against it, because that’s the part worth trusting.
Corrections in public. I’ve published numbers that turned out to be wrong and fixed them where anyone can see. That log is here, and it is deliberately not hidden.