I work on security as a systems problem. Give me a messy real-world substrate — certificates, malware, domains, threat feeds, models — and the job is the same: decompose it, build the system that makes sense of it, and reason about how it behaves under an adversary.
Right now that lens is pointed at an intersection few people occupy — agentic AI architecture, threat intelligence, and enterprise AI governance — designing the AI security systems large organizations trust to run in production, and deriving the strategy and frameworks from building them.
M.S., Cyber, Information & Operations (thesis track) — University of Arizona, conferred 2026
The next phase of AI security isn't bigger models — it's better systems: justified, minimal, and accountable. 📄 Read the thesis →
Four ideas it introduces:
| Principle | The idea |
|---|---|
| Necessity-First design | Every guardrail must justify its cost against the risk it removes. |
| Challenge Gates | Human-centric checkpoints where intervention actually matters. |
| Governance-as-Code | Controls expressed as machine-checkable artifacts, not PDFs. |
| Policy-as-Code | Continuously detect policy drift between stated policy and running behavior. |
AI Minimalism is one framework under the 0xSpectra umbrella — my independent research lab & publication. Its publication, Spectral Analysis, decomposes hard security systems into the parts that actually matter, one issue at a time.
Ja4-experimentation |
abac-ml-sim |
RetrographyRust · RetrographyPy |
RAG pipeline on AWS Bedrock for document analysis — applied LLM systems on managed infra. |
🚧 In progress — AI Minimalism tooling: a guardrail cost analyzer (is this control's overhead justified by the risk it removes?), a policy-drift detector, and governance-as-code references — turning the thesis into things you can run.
🎤 Two-time OpenSSL Conference speaker — 2025 · Prague 2026 → 📰 Peer-reviewed — ISCAP 2025 proceedings →
Open to advisory conversations on secure agentic architecture, AI evaluation, and AI governance.



