About me
What I’m working on and how I got here.
I’m a security engineering leader and researcher with more than 13 years across hands-on offensive security, security operations, and program leadership. My current work focuses on AI infrastructure and agent security.
The thread began before the job titles: a curiosity about how systems work, how they fail, and how to defend them. The journey below starts with my current research and moves backward through the roles that shaped that approach.
Professional journey · newest first
The work behind the current direction
2026–present
AI security research
Heron AI Security Fellowship · Apart Research · UBC
My current focus is AI × cyber: applying offensive, defensive, and operational security experience to distributed AI infrastructure and agent security while deepening my machine learning expertise.
Current work
- Researching attack surfaces in RDMA, InfiniBand/RoCE, NVIDIA GPUDirect, and distributed-training communication.
- Studying query-only attacks against long-term AI-agent memory through a UBC graduate course research project.
- Testing multi-agent behavior and the difference between short-lived behavioral effects and persistent trait change.
How I define the focus
I work from concrete systems questions: map the trust boundaries, test the assumptions, and state clearly what the evidence supports.
2025–present
Computer science and AI safety
I returned to school to understand modern AI systems from first principles and connect that foundation to my security experience.
What I have been learning
- Rebuilt the mathematical foundation through linear algebra, multivariable calculus, and probability.
- Studied machine learning, natural language processing, computer vision, and agentic systems.
AI safety and security programs & community
- Selected for CAMBRIA 2026
- Selected for AI Security Bootcamp (AISB), Las Vegas, 2026
- ML4Good Technical AI Safety Program, 2026
- BlueDot Impact Technical AI Safety, 2026
- UBC AI Safety Club
How my direction changed
Mechanistic interpretability initially appealed to the reverse engineer in me: understand a model internally, not only through its outputs. As I learned more, I shifted toward AI × cyber, where my existing experience offers more immediate leverage while I continue investing in the foundations.
2020–2025
Head of Information Security
I moved from red team to blue team, and from individual contributor to engineering leader, with a clear mandate: build a world-class Security Operations Center for the company operating Apple iCloud services in mainland China. I joined before the data center was operational. The site was literally still a hole in the ground. From there, I led security through buildout, launch, and mature 24/7 operations.
Selected work and outcomes
- Built the security function end to end, establishing the people, technology, operating model, and round-the-clock coverage for infrastructure serving more than 200 million users.
- Built and led the multidisciplinary security engineering organization spanning vulnerability management, detection engineering, incident response, security-tooling development, and site reliability engineering, and directed a $15M+ security program.
- Owned security architecture, operational readiness, executive risk decisions, procurement, and the MLPS and ISO certification work required to operate in a demanding regulatory environment.
Why I moved on
After five years, I had taken the organization from a data center still under construction to a fully operational security center. The mission I had accepted was complete and the team was in good hands. ChatGPT had also made the direction of technology difficult to ignore. Rather than move directly into another leadership role, I chose to step away and build the technical foundation for the next chapter.
2017–2020
Offensive Security Engineer Lead
I joined Amazon because I wanted to learn inside the company setting the standard that the rest of retail and e-commerce measured itself against. I began in internal audit; the security work I pursued there led to an internal move to the red team.
Selected work and outcomes
- Led red-team operations that uncovered vulnerabilities with potential financial impact in the tens of millions of dollars.
- Assessed high-value procurement and physical-security systems and helped drive systemic remediation.
- Identified monitoring gaps, presented at Amazon Risk Con in the United States and India, and worked with senior leaders on high-risk findings.
Why I took the next step
Amazon taught me how to find weaknesses at scale and how much work it takes to turn a finding into lasting change. I next wanted to own the defensive outcome over time: build the team, tooling, and operating model rather than hand over a report. AIPO Cloud offered that opportunity from the ground up.
2013–2017
Security analyst intern and IT auditor
My first enterprise-security experience was a rotational internship across vulnerability management, incident response, compliance, and other parts of the security team. I joined internal audit full-time because it offered an unusually broad view of how a large company worked.
Selected work and outcomes
- Identified serious weaknesses across retail, workstation, loyalty, and payroll systems and worked with teams on remediation.
- Built SOX audit dashboards that improved leadership visibility into audit execution.
- Worked across PHI and PCI compliance and was named Auditor of the Year in two consecutive years.
What set the direction
Audit gave me breadth, but I was consistently drawn to the moments when I could test whether a control actually held up. After four years, I wanted to go deeper in offensive security and learn inside the strongest technology organization in my industry. That led me to Amazon.
Speaking and community
Sharing practice across communities.
AI Security Forum · Washington, DC
Facilitated the Software Security for AI Systems workshop in a forum connecting policymakers, technical staff from frontier labs, and researchers.
Amazon Risk Con · United States and India
Presented emerging cybersecurity practices and secure engineering lessons to global developer audiences.
OWASP AppSec Days Pacific Northwest
Supported speaker coordination, registration, and attendee operations.
Education
- M.S., Information Systems and Operations Management at University of Florida
- B.C.S., Artificial Intelligence at University of British Columbia
- B.S., Finance and Animal Science at Northeast Agricultural University
Certifications
- Offensive Security Certified Professional (OSCP), 2024
- GIAC Certified Penetration Tester (GPEN), 2019
- Certified Information Systems Auditor (CISA), top 5% exam performance, 2016
- Certified Internal Auditor (CIA), 2016
Contact