featured project

S.H.I.E.L.D. Identity Registry

A realistic (but fake) identity system I built, then really attacked, detected, investigated, and secured, end to end.

Case no.
02
Status
In progress
Filed
MMXXVI

Also included. An AI-security track: testing an AI assistant built on the same registry data for security holes.

FastAPI + Keycloak Sigma / Elastic garak / ART

experience

One tour of duty, real clearance to talk about it.

Role
AI Security Research Intern, Team Lead
Where
AFRL, Rome Research Site
When
Summer 2026

Led a 3-person team measuring whether a predicted AI-risk score (OWASP AIVSS) matches what actually happens when you attack real AI agents.

  1. Ran adaptive indirect prompt-injection attacks against 7–8 open-weight LLM agents on rented GPU infrastructure, collecting 2,000+ real attack transcripts.
  2. Scored findings against U.S. Department of Defense outcome criteria (CNSSI 1253 / FIPS 199).
  3. Findings approved for public release (AFRL-2026-3601, PA-cleared 11 August 2026).
AgentDojo AIVSS / CVSS v4.0 CNSSI 1253 / FIPS 199 Adaptive Prompt Injection

Read the full case file →

skills

What's actually behind the projects above.

AI / LLM Security

Prompt Injection Testing Adversarial ML (ART) LLM Red-Teaming (garak) RAG Security & PII Redaction OWASP LLM Top 10 AIVSS / CVSS v4.0

Offensive Security

SQL Injection IDOR / Enumeration Attack Simulation MITRE ATT&CK / ATLAS

Detection & Response

Sigma Rules SIEM (Elastic Stack) Purple Teaming DFIR / Memory Forensics

GRC & Risk

Risk Registers DPIA Statement of Applicability NIST SP 800-61 CNSSI 1253 / FIPS 199

Cloud & Infrastructure

Docker Hardening Terraform / IaC Scanning IAM Least-Privilege Keycloak / OIDC

Engineering

Python FastAPI / Flask React Node / Express PostgreSQL / SQLite pytest / CI

certifications

Earned where I've earned it.

ISC2 Certified in Cybersecurity (CC)

Earned

Entry-level certification covering security principles, incident response, access control, network security, and security operations.

about

I like to prove things, not assert them.

I hold an AAS in Cybersecurity from LaGuardia Community College (CUNY, Dean's List, 3.66 GPA, June 2026), and I'm now a junior in the B.S. Cyber Security Systems program at St. John's University. I also completed NYC's Tech Talent Pipeline full-stack bootcamp and placed 3rd out of 20 teams at KEANCTF 2026.

My approach: build a system, attack it on purpose, and write down what breaks as carefully as what works. I think a project with no failures in it usually means something got left out.

I hold ISC2's Certified in Cybersecurity (CC), and I'm studying for CompTIA Security+ and Network+ using voice-driven study tools I built myself, since explaining an answer out loud forces better recall than flashcards.

contact

Let's talk.

Best reached by email or GitHub. Every project on this site links back to a repo or a write-up, and I'm happy to walk through any of it live.