Work With Me

The part where the terminal session ends and someone has to sign off on production.

Updated September 2026

Advanced Data Protection

Vectis protects sensitive data while preserving the operations an application actually needs. I help teams decide where that protection belongs and integrate it into systems that already have identity, storage, key management, and operational constraints.

  • Architecture and threat-model reviews.
  • Deployment and integration through HTTP, CLI, SDKs, and automation tooling.
  • Custom storage integrations and private builds when the environment requires them.
  • Applied cryptography using established libraries and explicit protocol boundaries.
  • Maintenance and support defined for the engagement.

Technical collaboration can also include early design feedback and joint work on integrations that are useful beyond one deployment. A review reduces uncertainty; it does not guarantee security or compliance.


Operational Simplicity

Kanso makes operational friction visible and gives teams a way to measure its cost. The work begins with evidence and a defined system boundary, not a promise of savings.

  • Training on friction detection, classification, and quantification.
  • Setup of the Friction Ledger for the system in scope.
  • Facilitation of the first Friction RCA.
  • A baseline Kanso Index using a consistent team, system, period, and cost basis.
  • Periodic reviews adapted to the Lite, Core, or Full implementation level.

The result is a working measurement process and a set of countermeasures the team can evaluate over time.


Secrets and PKI Infrastructure

I work with Vault, OpenBao, certificate authorities, and the infrastructure around them across on-premises, datacenter, cloud, and open-source environments.

  • High-availability and disaster-recovery architecture.
  • Upgrades, migrations, policy design, and authentication design.
  • Certificate lifecycle automation with cfssl, OpenSSL, and related tooling.
  • Dynamic secrets, credential rotation, and removal of credentials from repositories and pipelines.
  • Architecture reviews against an explicit threat model.
  • Network and access boundaries using controls such as pf and iptables.

This can include a migration from Vault to OpenBao when licensing, governance, or an open-source strategy makes that a suitable choice. The right destination still depends on the operating context.


API Security and Quality

Security findings are more useful when they are reproducible and connected to the system’s assumptions. I combine contract testing, dynamic analysis, load measurement, and threat modeling to produce evidence that engineering teams can act on.

  • OpenAPI contract testing with Schemathesis to detect drift between the specification and the implementation.
  • Dynamic assessment with OWASP ZAP against a disposable, isolated instance.
  • Load and latency baselines with k6 to measure current behavior and detect regressions.
  • Native fuzzing for parsers and validation boundaries.
  • SAST, DAST, and SCA controls integrated into CI/CD.
  • A written report covering evidence, assets, trust boundaries, assumptions, and residual risks.

These activities do not by themselves constitute a formal penetration test, certification, or guarantee that a system has no vulnerabilities.


Workflow

problem -> conversation -> scoped proposal -> delivery -> handoff
  1. You describe the problem, its context, and the constraints around it.
  2. A short conversation establishes whether the work is a good fit.
  3. A scoped proposal defines deliverables, assumptions, boundaries, and limits.
  4. The engagement produces a review, plan, integration, or operational baseline.
  5. The handoff records decisions, documentation, and residual risks.

How I Work

Just a message [email protected]

Most engagements start from a symptom, not a clean specification.


Disclaimer

Vectis and Kanso are open source, and that will not change. What isn’t on GitHub is time, judgment, and accountability under someone else’s constraints — that’s what I offer commercially.