Proof in public. Methods you can inspect.
The consulting approach is supported by published Product Security material, open technical work, field guides, and long-form engineering writing.
From connected vehicles to cloud attack paths.
Selected work that demonstrates adversarial thinking across cyber-physical products, cloud infrastructure, and modern software delivery.
EVSE & Electric Vehicle Product Security Casebook
A defense-oriented guide to treating EV charging platforms and software-defined vehicle ecosystems as cyber-physical Product Security systems — spanning cloud, APIs, device identity, CI/CD, firmware, OTA, telemetry, and recovery.
Preview the casebookEVSE Product Security · ArticleEVSE Is Not Just Another Web Application
A Product Security operating model centered on operational authority, attack chains, trust boundaries, secure release, device identity, and security leadership for electric mobility.
Read the articleAutomotive Security · Zero Nights 2017Tesla / CAN Bus Hands-on Research
A retrospective on hands-on work with real Tesla components, CAN traffic analysis, replay/fuzzing, and unauthorized command paths in a conference security challenge environment.
Read the research storyCloud Security · Attack Lab · RussianAWS SSRF → IMDS Credential Theft Lab
A sanitized technical lab showing how application-layer SSRF can reach EC2 metadata, expose temporary credentials, and expand into AWS IAM reconnaissance and cloud risk.
Read the AWS labProduct Security
Knowledge Base
A practical library spanning Product Security management, Secure SDLC, architecture, threat modeling, DevSecOps, API security, cloud, Kubernetes, software supply chain, metrics, and executive reporting.
Explore knowledge basePublished book · 156 pagesKubernetes Security
Guide
Attack surface, common risks, cluster security controls, attack scenarios, and CKS-oriented practical preparation.
View on GumroadAmazon publicationKubernetes Security on Amazon
The Kubernetes security book is also published through Amazon.
View Amazon listingEngineering repositoryDevSecOps Notes Box
Practical notes and reusable engineering references across AppSec, pipelines, cloud, containers, and Secure SDLC.
Open repositoryField guideGitLab CI/CD Hardening
Operator-focused guidance for trust boundaries, runner risk, secrets exposure, deployment governance, and audit readiness.
View resourcesOpen sourceK8-Shield
Kubernetes-focused security checking and hardening-oriented technical work.
Open projectLong-form writingProduct Security Writing
Technical and strategic writing across Product Security, DevSecOps, AppSec, cloud security, and engineering practice.
Read on DEVA consulting methodology should leave evidence behind.
Public work is not a substitute for client-specific analysis. It is a way to show the depth, vocabulary, and engineering principles behind an engagement before the first call.
Use the material to evaluate fit before you engage.
If the way the work is framed matches your engineering reality, the next step can be a small, focused assessment.