I build and lead product security programs that keep regulated, safety-critical products secure across their full lifecycle — without slowing the engineers who build them. 20+ years across medical devices, connected systems, and enterprise cybersecurity, including director-level leadership and 21 years of U.S. Army service as a Sergeant First Class (E-7). Founder of DMCS Labs. I contribute cybersecurity content directly to FDA 510(k) submissions, stand up threat modeling and PSIRT programs, and embed security into CI/CD.
-
FoundryGuard — AI Security Gateway & Firewall (Python / FastAPI)
Inspects prompts and agent actions and enforces policy — prompt-injection defense, agent authorization, secret & PII redaction, risk scoring, and tamper-aware audit logging. Zero-trust and human-in-the-loop controls mapped to OWASP LLM Top 10 and MITRE ATLAS. -
AppSec Intelligence Platform — DMCS Labs (Python / Flask)
Application security risk & compliance decisioning: asset inventory, findings management, contextual + CVSS risk scoring, threat modeling, compliance posture, and audit logging, rolled into executive remediation-prioritization dashboards. -
AI Prompt Injection Security Lab (Python / Flask · Azure OpenAI)
Flask application integrated with Azure OpenAI to detect and block prompt injection and adversarial inputs. Includes automated red-team testing and security reporting. -
SifraAI Security Studio v1.0 Beta (in active development)
GUI-first, authorization-based AI security testing platform for LLMs, RAG systems, agents, AI endpoints, and AI infrastructure. -
Cyber Procedure Questionnaire
Procedure-discovery tooling for building operational, audit-ready security procedures aligned to the SSP and control matrix.
Note: the platforms above are research / lab builds, not production-hardened.
- Product Security Engineering & Program Leadership
- Medical Device Security (FDA 510(k)/PMA · Section 524B · IEC 62304 · ISO 14971)
- Secure SDLC · Threat Modeling (STRIDE) · DevSecOps · SBOM/VEX · PSIRT
- AI / LLM & Agentic Security (OWASP LLM Top 10 · MITRE ATLAS · NIST AI RMF)
- GRC (NIST CSF · NIST 800-53 · ISO 27001)
- M.S., Cybersecurity & Cyber Operations — ECPI University (GPA 3.98 / 4.0)
- B.S., Computer Science (Magna Cum Laude) — Trident University International
- CISM (ISACA) · CISA (ISACA) · CEH (EC-Council) · CompTIA Security+ · ISC2 CC
- Microsoft: Cybersecurity Architect Expert (SC-100) · Identity & Access Administrator (SC-300) · Azure AI Engineer Associate
- Governance, Risk & Compliance Auditor (GRCA)
View verified certifications on Credly
LinkedIn · 📍 Rockwall, TX ·