
Cybersecurity
Least privilege without the friction
Everyone agrees with least privilege until it slows them down — then the wildcards creep back in. Here's how I make tight IAM the path of least resistance instead of a tax.
· 2 min read
Writing
Notes on compliance, cybersecurity, DevOps, and applied AI — the four pillars, in long form.

Cybersecurity
Everyone agrees with least privilege until it slows them down — then the wildcards creep back in. Here's how I make tight IAM the path of least resistance instead of a tax.
· 2 min read

DevOps
Most 'big bang' platform migrations don't fail on the technology — they fail on coordination. Here's the runbook I use to move a live system to Kubernetes one slice at a time, with a rollback at every step.
· 2 min read

Compliance
Audit season shouldn't be archaeology. Here's how I turn a handful of ISO 27001 controls into automated checks that run on every pull request — so evidence is a by-product of shipping, not a fire drill.
· 2 min read

AI
Shipping an AI feature without evals is flying blind — you only learn it regressed when a user does. A small, boring evaluation harness in CI fixes that, and it's less work than the first incident.
· 2 min read

AI
Agent demos are easy; agents that survive contact with real operations are not. Notes from putting multimodal RAG and agent workflows into production.
· 2 min read

Compliance
Compliance fails when it reads like paperwork. Here's how I frame an information security management system as a product engineers actually use.
· 2 min read