Just like information security, I am socio-technical: I build tools and systems that solve real problems, automate unnecessary toil, and help people make better security decisions.
I am a threat research and detection engineer with 14+ years of experience across security operations, DFIR, security architecture, product leadership, and software engineering. I have built open-source tools, led products used by more than 18 million people, and helped design and operate Go and Python services that process billions of security events daily.
My current work sits at the intersection of threat research, phishing defense, behavioral detection, security automation, and agentic systems. I enjoy taking ambiguous security problems and turning them into reliable detections, useful tooling, scalable services, and workflows that keep human judgment in the loop.
Earlier in my career, I worked in phishing defense, vulnerability management, digital forensics, incident response, and enterprise systems administration. That foundation, including Active Directory, Group Policy, PowerShell, endpoint management, and server administration, still shapes how I approach security engineering today.
I am GIAC GCWN certified and previously held the GCFA. I write, present, and build in the open at letsautomate.it.
Defensive Systems — Detection engineering, validation, adversary simulation, security automation, and operational reliability.
Security Intelligence — Threat research, phishing infrastructure, behavioral analysis, capability discovery, and adversary-focused investigation.
Cognitive Security Systems — Agentic tooling, knowledge representation, orchestration, reasoning, and human-in-the-loop security workflows.
Engineering — Go and Python services, distributed systems, high-volume event processing, APIs, automation, and operational tooling.
Sublime Security (June 2026 to Present)
I research threats and build detections, tooling, and frameworks to improve phishing defense through better behavioral detection and analyst-facing workflows.
14+ years across Sublime Security, AppOmni, Red Canary, Swimlane, Cofense, and the University of Missouri — spanning security operations, DFIR, detection engineering, security architecture, product leadership, and software engineering. Earlier work included Windows infrastructure, Active Directory, Group Policy, PowerShell, vulnerability management, and incident response.
Full history: letsautomate.it/page/about
I have built and contributed to open-source projects used across the security engineering community. I am also an official maintainer of Atomic Red Team.
- pyattck — Python package for working with MITRE ATT&CK
- atomic-operator — Python framework for executing Atomic Red Team tests
- soc-faker — Synthetic data generation for security operations and automation
- opencti-enrichment — Go service for OpenCTI observable enrichment
- ai-router — Python CLI for routing local Ollama models based on available system resources
More open-source projects · GitHub
I write about security engineering, detection, automation, software systems, defensive research, and the social and technical implications of AI at letsautomate.it.
- Beyond the Prompt: The Social Costs of Generative Artificial Intelligence
- The Agentic Web: A New Internet Built for Agents, Not Browsers
- How I Use LLMs for Security Work: Part 2
- How I Use LLMs for Security Work
- My Thoughts About the United States Banning TikTok
Beyond the Prompt: The Social Costs of Generative Artificial Intelligence
Published in the Business, Entrepreneurship & Tax Law Review, Vol. 10, Issue 1 (2026).
- Official maintainer of Atomic Red Team
- Past President and Board Member, Central Missouri InfraGard chapter
- SC Media Reboot Leadership Awards 2019 — Influencer
- Contributing author to Tribe of Hackers: Blue Team
- GIAC Certified Windows Security Administrator (GCWN)
- Previously held GIAC Certified Forensic Analyst (GCFA)
- Hunting PhishKits - 2022 CactusCon
- atomic-operator: Atomic Red Team Python Execution Framework - 2022 CactusCon
- Making MITRE ATT&CK Actionable - 2020 Hacker Halted
- Securing Windows with Group Policy - 2021 CircleCityCon
- Hunting Phish Kits - 2019 DerbyCon
Full list: letsautomate.it/page/presentations






