Consulting
Work with me
Some problems don't need another deck. They need someone who'll get inside the system, work out what's actually failing and help your team fix it without creating a second problem on the way.
I take a small number of engagements across security, AI and the overlap between them. I build security programs, repair ones that aren't working and help leadership teams make decisions about AI risk. I also review incidents and system designs, including systems built around language models and AI agents. Problems that don't fit neatly into those categories are often the most interesting.
If you're in the middle of something complicated, tell me what you're trying to solve. I'll tell you quickly if I think I can help, and I'll say so if I can't.
Where I tend to be useful
- Security leadership and program design
- Security for language models and AI agents, including attacks against them
- Incident response, security engineering and architecture review
- Security operating models, technical risk and compliance readiness
- Part-time or temporary security leadership when a team needs experienced coverage
25+ years in security across Microsoft, Netflix and Meta. I helped create the Netflix SIRT, helped grow the security organization there from 4 engineers to 100+, and was Principal Security Engineering Manager for CodeQL at Microsoft, where the program took code scanning from minimal coverage to 90%+ across Windows, Xbox, Office 365 and other codebases. Now I work hands-on with AI and LLM systems.
More detail on each of those areas: security leadership and program design, AI and LLM security, and incident response and architecture review.