01
Hardware-rooted secrets
Architected the Secure Secret Storage Solution (S4), binding secret access to workload identity with vTPM-backed non-extractable keys, HSM-protected storage, and audited air-gapped provisioning.
New York · Lead Engineer, Platform Engineering
I design and build security-critical systems spanning zero trust, cryptographic key management, trusted computing, cloud platforms, and AI infrastructure.
What I do
My work spans zero-to-one security architecture, hands-on implementation, production operations, and technical leadership. At Bullish, I progressed through Technical Services, Infrastructure, Secure Infrastructure, and Platform Engineering—expanding from exchange operations into platform security, hardware-rooted trust, cryptographic systems, and secure AI infrastructure.
Selected impact
Systems and controls built to withstand scrutiny, reduce risk, and become dependable parts of how the business operates.
01
Architected the Secure Secret Storage Solution (S4), binding secret access to workload identity with vTPM-backed non-extractable keys, HSM-protected storage, and audited air-gapped provisioning.
02
Built and operated zero-trust access architecture, managing Okta and Zscaler while engineering the authentication and always-on VPN components used across the organization.
03
Defined and implemented cryptographic key-lifecycle architecture and controls for security-critical custody and exchange workloads.
04
Led threat modeling and security design reviews, embedded secrets, container, and code scanning into CI/CD, and partnered with internal and external penetration testers through remediation.
05
Productionized an organization-wide AI gateway used by hundreds of people, adding identity, observability, reliability, model routing, governance, and fine-grained cost attribution.
06
Worked directly with Google Cloud engineers to diagnose and help remediate Confidential Compute live-migration defects involving memory synchronization and vTPM state.
Experience
Lead Engineer, Platform Engineering
Platform Security & Secure Infrastructure. Progressed through Technical Services, Infrastructure, Secure Infrastructure, and Platform Engineering.
Zero trust, platform security, and trusted computing
S4 secrets architecture, HSM/vTPM, and PKI/MPC key lifecycle
Threat modeling, secure delivery, and cross-functional security leadership
Enterprise AI infrastructure and developer tooling
Senior Engineer, DevOps
Led DevOps during the founding of a blockchain-based social platform, owning platform infrastructure, blockchain operations, delivery systems, and production operations.
Senior Engineer, DevOps / Portfolio Technical Lead
Built products, security systems, and highly available infrastructure across TheNumber, PhoenixABS, Better Mortgage, and Climb Credit.
Lead Engineer
Led development of native iOS and web applications designed to improve the customer experience.
Open source
I contribute fixes where security, platform engineering, and AI infrastructure meet the real world—from cloud providers and ML build systems to gateways and infrastructure tooling.
Prevented pip installations from producing native extensions for the wrong Python interpreter.
View contributionAdded a missing Compute Engine guest OS feature value used by the Terraform provider.
View contributionCorrected strict-shell handling of an empty platform argument array.
View contributionExtended the multi-agent terminal workflow to detect and operate Google's Gemini CLI.
View contributionAdded a production-driven transport path for Datadog Operator environments.
View contributionFixed plan-time validation when location values are unknown until apply.
View contributionAbout
I am most energized by work without a ready-made playbook: research the system, understand the failure modes, prototype carefully, and turn the result into something people can trust.
Security has been a throughline throughout my career—from high-security authentication and HIPAA infrastructure to zero trust, HSM/vTPM-backed secrets, PKI/MPC, confidential computing, and secure AI platforms. I stay hands-on while helping security teams, engineers, and executives reason clearly about difficult technical choices.
Industry engagement
Selected attendee in 2026 for technical dialogue on ultra-low-latency cloud architecture, kernel-bypass networking, virtualization jitter, and precision time synchronization.
Education
B.A., Liberal Arts and Sciences / Liberal Studies
Entrepreneurship and Business Management
Outside work
I’m a husband, proud uncle and godfather, longtime meditation practitioner, and lifelong snowboarder and skateboarder. I organize New York City’s Onewheel community, enjoy the occasional security challenge, and keep a steady stream of side projects in motion.
Contact