Privileged Access
CyberArk & Vendor PAM
Securing, vaulting, and monitoring privileged accounts across the enterprise — plus an ongoing zero-trust rollout replacing standing vendor VPN access with just-in-time, session-isolated browser gateways.
Network Access Control
Forescout NAC
Real-time visibility and compliance enforcement across every connected device — IT, IoT, and OT — using 802.1X and dynamic VLAN segmentation to isolate rogue endpoints the moment they appear.
Asset Attack Surface
Axonius CAASM
Aggregating data from across the security stack into one correlated view of every asset — reconciling conflicting sources and surfacing the blind spots where devices were missing endpoint telemetry.
Identity & MFA
Entrust 2FA
Enterprise multi-factor authentication across VPNs, portals, and stubborn legacy systems — RADIUS, SAML/OIDC federation, and hybrid hardware/software tokens hardening the identity perimeter at scale.
The same instinct — understanding a system deeply enough to reshape it — runs through the rest of my work, from decoding ancient texts to building open tools.
Let's secure what you're building
Whether it's hardening distributed infrastructure, designing zero-trust access, or comparing notes on the craft — I'm open to connecting.