I design and build trusted, measurable business workflows using AI, cloud infrastructure, automation, and security-first engineering.
My work focuses on turning AI from an isolated tool into an operational system—one that can be evaluated, governed, observed, and safely connected to business processes.
Secure it. Automate it. Observe it. Scale it.
I am a U.S. Army veteran and technology professional with more than 25 years of experience learning, building, troubleshooting, and improving technical systems.
Today, I work at the intersection of:
- AI agents, RAG, MCP, and workflow automation
- AWS and Azure cloud architecture
- DevOps and DevSecOps delivery pipelines
- Agent identity, delegated authority, and runtime authorization
- Observability, evaluation, governance, and human oversight
I build systems that are secure, maintainable, observable, cost-aware, and designed for real operational use—not just demonstrations.
Secure Kubernetes Agent Platform — Planning
A cloud-native platform for running AI and coding agents as governed workloads, with an AI gateway, MCP gateway, workload identity, end-to-end tracing, per-tool authorization, and isolated execution environments. AWS/EKS is the initial reference architecture, with Azure and GCP variants planned.
- Secure AI agents, RAG systems, and MCP-enabled workflows
- Evaluation pipelines and CI quality gates for AI applications
- Human-approved automation for high-impact business actions
- Cloud infrastructure with Terraform and CloudFormation
- CI/CD pipelines with SAST, DAST, SCA, secrets, container, and IaC scanning
- Agent identity, least-privilege permissions, and runtime policy enforcement
- Monitoring, logging, cost tracking, and operational dashboards
- Responsive applications, APIs, dashboards, and workflow tools
Built a Docker-based security pipeline for a simulated fintech platform. GitHub Actions runs unit, integration, smoke, SAST, DAST, SCA, secrets, and infrastructure checks from pull request through staging validation.
Stack: Docker · GitHub Actions · DevSecOps · CI/CD · SAST · DAST · SCA
Repository: operation-aegis
Case study: How I Built a Docker-Tested DevSecOps Pipeline
Built an AWS compliance auditing tool that inventories cloud resources, uses temporary credentials, records structured API evidence, and exposes findings through an API.
Stack: AWS · IAM · Terraform · Python · boto3 · GitHub Actions OIDC
Repository: audittrail-sdk
Case study: I Built an AWS Compliance Auditor That Uses No Static Keys
Built a cloud-native system that detects AWS security events, performs controlled serverless remediation, and provides evidence through CloudTrail, EventBridge, Lambda, CloudWatch, SNS, X-Ray, retries, and dead-letter queues.
Stack: AWS · Terraform · Lambda · EventBridge · CloudTrail · CloudWatch · GitHub Actions
Repository: project-sentinel-terraform
Case study: Building a Self-Healing Cloud Security System
Expanded an S3 troubleshooting lab into a repeatable DevSecOps deployment pipeline with CloudFormation, GitHub Actions, security gates, post-deployment HTTP checks, and documented remediation evidence.
Stack: AWS S3 · CloudFormation · GitHub Actions · IAM · Checkov · Snyk · cfn-lint
Repository: aws-cloudmart-secure-web-assets
Case study: From S3 AccessDenied to DevSecOps
- Deterministic controls for security decisions: models may explain findings, but policy and authorization determine whether actions proceed.
- Verify before execution: identity, delegated authority, purpose, resource, context, and current permission must be checked before a tool call or state-changing action.
- Human oversight based on reach: higher-blast-radius actions require stronger approval, containment, and stop authority.
- Evidence across the execution chain: prompt → plan → tool call → command → system activity → result → verification.
- Build–Verify–Destroy: cloud labs are validated and then removed to control cost and reduce unnecessary exposure.
- Turning AI into trusted, measurable business workflows
- Building evaluation, remediation, and governance systems for AI applications
- Securing agent tools, data access, delegated authority, and runtime execution
- Expanding production-style AWS, DevOps, and DevSecOps implementations
- Preparing for AWS AI Practitioner and AWS Developer Associate certifications
Metrics are generated daily by GitHub Actions and stored in this repository.
I contribute to The DevSec Blueprint (DSB) and continue building practical cloud security and DevSecOps projects through community-based learning and collaboration.
Community repository: The DevSec Blueprint




