featured project
S.H.I.E.L.D. Identity Registry
A realistic (but fake) identity system I built, then really attacked, detected, investigated, and secured, end to end.
Also included. An AI-security track: testing an AI assistant built on the same registry data for security holes.
experience
One tour of duty, real clearance to talk about it.
Led a 3-person team measuring whether a predicted AI-risk score (OWASP AIVSS) matches what actually happens when you attack real AI agents.
- Ran adaptive indirect prompt-injection attacks against 7–8 open-weight LLM agents on rented GPU infrastructure, collecting 2,000+ real attack transcripts.
- Scored findings against U.S. Department of Defense outcome criteria (CNSSI 1253 / FIPS 199).
- Findings approved for public release (AFRL-2026-3601, PA-cleared 11 August 2026).
featured projects
Three real projects, each with a full write-up.
S.H.I.E.L.D. Identity Registry
A realistic (but fake) identity system I built, then really attacked, detected, investigated, and secured, end to end. Also includes testing an AI assistant built on the same data for security holes.
ChuckSpot
A tool that helps NYC food truck owners decide where to park. It combines live event, weather, and cost data to estimate profit for each event.
AFRL_AIAI
Led a 3-person research team at the Air Force Research Lab. We tested whether a predicted AI risk score actually matches what happens when you attack real AI agents, scored against U.S. Department of Defense standards.
skills
What's actually behind the projects above.
AI / LLM Security
Offensive Security
Detection & Response
GRC & Risk
Cloud & Infrastructure
Engineering
certifications
Earned where I've earned it.
ISC2 Certified in Cybersecurity (CC)
EarnedEntry-level certification covering security principles, incident response, access control, network security, and security operations.
about
I like to prove things, not assert them.
I hold an AAS in Cybersecurity from LaGuardia Community College (CUNY, Dean's List, 3.66 GPA, June 2026), and I'm now a junior in the B.S. Cyber Security Systems program at St. John's University. I also completed NYC's Tech Talent Pipeline full-stack bootcamp and placed 3rd out of 20 teams at KEANCTF 2026.
My approach: build a system, attack it on purpose, and write down what breaks as carefully as what works. I think a project with no failures in it usually means something got left out.
I hold ISC2's Certified in Cybersecurity (CC), and I'm studying for CompTIA Security+ and Network+ using voice-driven study tools I built myself, since explaining an answer out loud forces better recall than flashcards.