About

I'm an architect and technology leader with 19+ years building large-scale, business-critical systems. Writing on platform engineering, DevSecOps, IAM, supply chain security, observability, and agentic AI from a practitioner's perspective.

I design platforms that turn business strategy into engineering reality: modernizing legacy estates with cloud-native architecture, embedding security and observability into solutions, integrating agentic AI and GenAI into developer workflows, and scaling productivity across distributed engineering teams. Representative outcomes include roughly 40% improvement in system reliability, 50% reduction in time-to-market, 25% lift in program adoption, and platform capabilities serving 10+ enterprise customer accounts and 35+ engineers.

This site is where I write long-form — mostly for peers who build and run platforms, not for product launches. The topics follow whatever I am working through in practice: architecture, security, supply chain, observability, and how AI shows up in real engineering organizations.

For role-by-role history, skills, and a PDF download, see the résumé. Recent posts are on the blog.

Core focus

  • Agentic AI and GenAI in the SDLC — LLM-powered automation, copilots, and agentic developer experience
  • Platform engineering and internal developer platforms on Kubernetes and multi-cloud
  • DevSecOps and software supply chain security — SBOM, SLSA, in-toto, zero-trust IAM
  • Cloud security and compliance — AWS, Azure, GDPR, NIST CSF, CIS
  • Architecture governance, North-Star vision, and engineering leadership at enterprise scale

Where I have applied it

Telecom modernization, SaaS across B2B, B2C, and B2B2C models, enterprise application security (zero trust, PKI, regulatory compliance), digital transformation and SaaS monetization, and IoT fleet management at scale.

What I write about

  • Platform and security architecture for large, regulated systems
  • DevSecOps and supply chain security in production, not slide decks
  • Agentic AI and GenAI inside developer workflows — guardrails, identity, and operations
  • Field notes from work that did not go as planned, including when tools or assumptions were wrong

Find me

If you are working on platform engineering, supply chain security, or enterprise adoption of agentic AI — I am happy to compare notes.

Colophon

Built with Jekyll, hosted on GitHub Pages, set in Fraunces and Inter Tight. Source on GitHub.