RootReap3r.
Focus areas
Nation-state TTP attack engine
Built a red team engine auto-generating live attack scenarios from nation-state TTPs via MITRE ATT&CK/ATLAS, compressing adversary emulation cycles from weeks to hours.
RAG & MCP exploitation research
Red-teamed multi-modal RAG pipelines and MCP exploitation chains on nuclear-classified infrastructure; hardened findings into enforceable governance controls.
TS/SAP vulnerability discovery
Surfaced previously unknown TS/SAP vulnerabilities through adversarial analysis beyond automated tooling, converting findings into IR tabletop scenarios to close gaps before nation-state exploitation.
NC3 / nuclear ATO authorship
Authored ATO packages (~2,500 controls, SCTMs, SSPs) as Lead ISSO for Sentinel and Nuclear Command & Control programs. Led accreditation lifecycle across 10 packages for a $147B government program, mapping artifacts against all 20 NIST Rev 5 control families to achieve full ATO.
Experience
AI Red-Teamer / AI Security Engineer (Contract)
- Exploited 100+ direct and cross-domain prompt-injection/jailbreak vulnerabilities across client LLM-integrated products within the first week, validated and scored via structured red-team taxonomy.
- Built and deployed a multi-tenant AI chat widget embeddable on any site in <30 min, with production-grade security: CORS allowlisting, prompt-injection screening, XSS-safe rendering, CSRF protection, timing-safe auth.
- Surfaced MCP tool-poisoning, schema injection, and cross-server privilege escalation via over-privileged server exploitation across client AI tool infrastructure.
Senior Cybersecurity Engineer
- Conducted adversarial security impact assessments on 2,700+ deliverables across software, hardware, networks, and AI/ML systems for a $147B TS/SAP cloud program, certifying risk disposition through malware analysis and vulnerability scanning.
Security Program Manager
- Ran adversarial assessments across physical, INFOSEC, COMSEC, and cyber controls protecting $41M+ in CNWDI/DOE Restricted Data across two SAP/TEMPEST vaults, closing every exploitable gap found.
Cyber Automation Lead
- Built PowerShell/Python automation for account remediation and IR triage, cutting escalation decision time on leakage/compromise cases from minutes to seconds across DISA, White House, and Pentagon.
Cyber Investigations Lead
- Led response to the 2019 credential-stuffing campaign compromising 900+ accounts, correlating device/IP/geolocation/VPN signals to restore 100% of accounts to original owners.
Incident Response Lead
- Advanced from help desk analyst to IR Lead, resolving 10,264 tickets and coordinating a multi-person IR team while sustaining a 96% stakeholder satisfaction scorecard.
Military Service
Weapons Director
A Weapons Director sits in an Air Operations Center or Control and Reporting Center, watching a live radar picture and directing fighter aircraft in real time — sorting real threats from noise, prioritizing which contact gets worked first, and issuing short, unambiguous instructions to pilots who are relying on your read of the situation because they can't see what you can see. It's high-tempo decision-making under incomplete information, inside a strict rules-of-engagement framework, where a wrong call has immediate consequences and there's no time to second-guess.
That's a closer match to AI red-teaming and incident-response work than it might sound: triaging a flood of findings in real time, deciding what's a real threat versus noise, working inside an explicit scope/rules-of-engagement boundary, and communicating clearly and fast when the picture is incomplete. The instincts built directing intercepts translate almost directly to directing a red-team engagement or running point during a live incident.
This scene (from a film, not real footage) captures the tempo and stakes of directing air assets in real time — the closest illustration I've found of what that decision-making tempo actually feels like.
Also fiction, not real footage — but the command-and-control room in this scene is a reasonable stand-in for the kind of operations floor a Weapons Director actually works from.
Education & Awards
M.S. Artificial Intelligence · Georgia Institute of Technology
In progress (part-time). Research: adversarial robustness & red-teaming of LLMs and agentic systems.
B.A.S. Cyber Operations, Defense & Forensics · University of Arizona
NSA Center of Academic Excellence in Cyber Operations; malware reverse engineering, digital forensics.
AFNWC Security Community Award · Air Force Nuclear Weapons Center
Security Outstanding Team Award, NXOS Security Team. Also: Minuteman III Personnel Award, ICBM Personnel Award.
Interactive certification roadmap
Click a node. Gold = completed, purple = in progress. Concept-based progression by rarity, domain, and offensive vs. defensive focus.
Click any certification above to view domain alignment, rarity, and offensive/defensive weighting.
Deciding which cybersecurity certification to pursue next? See the full interactive security certification roadmap — a concept-based breakdown of certs by rarity, domain, and offensive vs. defensive focus.
Projects
AI-Powered Active Defense & Threat-Hunting Platform
Multi-agent active-defense platform using ML-based C2 beacon detection, passive attribution (geolocation, JA3, threat-intel), confidence-gated response, and cryptographic chain-of-custody evidence; shipped 105 passing tests and one-command FBI/CISA report generation (STIX 2.1, IOC).
LLM Safety-Evaluation Harness
Red-team harness replacing self-graded LLM safety scoring with deterministic pass/fail gates (canary extraction, PII regex, injection detection) and an advisory-only LLM judge calibrated against a golden set, aligned to NIST AI RMF MEASURE/MANAGE, with a code-enforced allowlist immune to prompt-injection scope escape. Read the technical breakdown →
AI-Driven NIST 800-53 Rev 4→5 Migration Pipeline
Pipeline generating SCTM, eMASS export, and POA&M items from SSP content, grounding every AI judgment against the full 1,189-entry NIST Rev 5 catalog; provider-agnostic (Anthropic/OpenAI/Bedrock GovCloud), deployable air-gapped/NIPR with zero code changes.
Adversarial LLM Incident-Response Tabletop Engine
Self-contained engine where an LLM plays a state-consistent threat actor across 23 scenarios and 9 MITRE-mapped APT profiles, with attacker/grader roles split across separate API passes and offline .docx after-action reports.
Writing
From Cryptic Commands to Agentic CLI: How Claude Code Rewired the Terminal
Why decades of memorized flags and manual scripting are giving way to natural-language, autonomous terminal work — with a side-by-side comparison of manually diagnosing a broken service versus letting Claude Code do it end-to-end.
From Tool Mastery to Agent Orchestration: How AI Rewired Offensive Cybersecurity
How agentic AI reshaped offensive security between 2016 and 2026 — RoE-gated agent orchestration, hyper-scale recon, exploitation chaining, the global AI tooling landscape, and the AI-vs-AI attack surface: indirect prompt injection, context poisoning, and agent hijacking.
My First Week in Professional AI Red Teaming: What Nobody Tells You
Field notes on an unexpectedly diverse team, exploiting 100+ vulnerabilities in a week, and a recognition gap around obfuscated prompt injection — with two rewritten examples showing a real finding versus one that isn't.
Building recon-sweep: A Scope-Gated Harness for Agentic AI Red Teaming
Inside recon-sweep's architecture — code-level scope-gated pentesting and falsifiable, canary/PII/injection-gated AI evaluation instead of LLM self-grading.
Before ChatGPT: The First AI Jailbreak Community Nobody Talks About
A firsthand account of adversarial prompting against Midjourney's content filter months before ChatGPT's "DAN" prompts — and why keyword/semantic-matching guardrails still fail the same way today.
Tooling & frameworks
certs SecAI+ (Beta Passer) · CASP+ · PenTest+ · Security+ · PWPE (<100 holders worldwide) · PNPT · eCPPTv3
report turned in COAE (HTB AI Red Teaming) — awaiting results
in progress OSAI+ (Offensive Security)