I spent a year running vulnerability management for a hospital system — then built the tooling the job kept asking for, and shipped it the way a vendor would: Store-certified, code-signed, and run through my own security gauntlet.
I've worked the vulnerability-management seat and built the tooling around it, so I land in one of three places — and I'm useful on day one in any of them.
Platform operations, SLA policy design, KEV-driven prioritization, and getting findings to the owner who can actually fix them. I did this in a HIPAA/ePHI hospital environment — then built the dashboard I wanted while doing it.
Python tooling operators actually use: pipelines that stay responsive on multi-million-record datasets, integration with the ticketing system of record, and a mock environment so nothing is ever tested against production.
Static analysis, dependency and secret scanning, SBOM, code signing and Store certification, wired into one repeatable gate a release has to clear — with a dated evidence bundle at the end of it.
What you'd get in the first 90 days: an honest read of where your SLA clocks actually stand, the findings that will breach next sorted ahead of the ones that already did, ownership mapped so nothing sits unrouted, and the manual reporting steps someone repeats every week turned into something that runs itself. I've done each of those — the difference is I'd be doing them for your estate instead of building the tool for mine.
The case studies are the heart of this site: real problems I hit, the root cause, the engineering, and the proof — including the ones where no off-the-shelf answer existed and I had to invent one.
A Windows desktop app for VM teams: which findings are about to breach SLA, who owns the assets, and what got done about it. Store-certified, IV code-signed.
read more →
Five problems, written the way I hit them: millions of findings on one desktop, ownership routing, zero-day exposure answers in seconds, the attack surface nobody scans, and letting operators customize ticket fields without handing them an injection vector.
read more →
A compliance gauntlet I built, with pass/fail criteria and evidence artifacts, plus RFC 6962 Merkle logs, DSSE/in-toto provenance, and a real disclosure policy.
read more →
The remediation pipeline and test infrastructure around the analyzer: idempotent ticketing, an encrypted dispatch layer, and a full mock-ServiceNow environment.
read more →Security tooling is where I go deepest — but I range across the whole stack, from a local-AI homelab to desktop tools. Same builder's instinct, different canvases.
A self-hosted, all-AMD workstation (no CUDA): local LLMs at 100% GPU on ROCm, image generation, and MCP agents that drive Blender and Unreal directly. Getting there meant root-causing a bleeding-edge RDNA4 bug that had inference silently falling back to CPU — and fixing it.
Ollama · ROCm · LM Studio · gpt-oss / Qwen / Llama-vision · MCP
A release-signing tool rendered as frameless, translucent "bubble" windows that dock to any screen edge; when the pipeline is ready, the final bubble runs a live signing ceremony that pauses, pulsing, for the physical YubiKey touch. Distribution-aware and self-hosting — it signs its own build.
Python · PySide6 · QThread · cloud-HSM signing · YubiKey · Authenticode + RFC-3161
Sensitive data on my NAS stays encrypted and only becomes available when I physically touch a hardware key — with a security console that shows every request: who asked, from where, and when. The same request → notify → approve pattern guards the demo downloads and private pages on this site, so nothing is released without a deliberate, logged, human approval.
Hardware-key approval gate · encrypted at rest · full audit trail · live in production. Architecture available on request.
A vulnerability-management practitioner who builds — happiest in a terminal, chasing a problem until the solution is simple and holds up.
I'm Elliot. I spent the last year on a vulnerability-management team in a hospital system — HIPAA, ePHI, real SLA clocks, and findings that had to reach the right owner before they aged out. Everything on this site came out of that seat: I kept hitting gaps no product filled, so I built what the job was asking for. I came up the formal way — a summa cum laude cyber degree, Security+, CEH — but I learn fastest by building, and I validate everything against the source instead of taking it on faith. I get genuinely obsessed with a hard problem: I'll rough out three approaches, throw two away, and keep refining until what's left is simple, honest, and holds up under its own edge cases.
I hold several threads at once by habit — carrying contingencies for the failure that hasn't happened yet while keeping a clear line to the outcome I'm steering toward. It's why I'm drawn to the problems nobody has mapped, and why the next two moves are usually ready before the current one lands.
How I think:
Where I'm strongest:
Underneath it all is a genuine love of the craft — the discovery, the learning, the building — which is why the work spills across security, local AI, and infrastructure alike. More on my background, certifications, and working principles on the about page.
Open to new roles in vulnerability management, security tooling, and security software engineering. Email is the best way to reach me, and I'm happy to give a live demo — or you can request a demo build directly.