I build security tooling: compiler-level static analysis, systems-level vulnerability review, and a growing focus on Linux systems and graphics-driver work. Based in Phoenix, AZ, August 2026.
I build security tooling: static analysis that catches vulnerability classes other tools miss, and systems-level review grounded in real compliance work. I'm looking for security or systems engineering roles, and building toward Linux graphics and driver work as a longer-term direction.
My M.Sc. thesis is a Clang-Tidy static analysis tool that catches trust-boundary information leakage in C/C++: programs that are syntactically correct and free of undefined behavior, but still leak sensitive data across a trust boundary through object representation and struct padding, a class of bug conventional scanners miss entirely. It draws on some formal-methods groundwork underneath, but the tool itself is the point: evaluated on real-world C libraries with zero false positives.
I'm currently building Project Datum, a multi-year effort to make the Linux gaming graphics stack measurable and reproducible. Today, when a frame is late, the cause is buried across game, translation layer, driver, kernel, and compositor, with no unified view across the boundary. I'm early: working through Vulkan fundamentals, reading the source of MangoHud and Gamescope, and standing up a non-NVIDIA machine, before I start contributing upstream and building the measurement tooling itself.
Before this: six years as an Information Systems Security Officer in the Air National Guard, running security authorization and continuous monitoring for a mixed classification environment, including TEMPEST and COMSEC responsibility.
The Linux gaming graphics stack is a tower of opaque, interacting layers: game binary, translation layer, Vulkan, userspace driver, kernel graphics subsystem, compositor. When a frame is late, no single tool sees why. Project Datum is a measurement substrate for cross-layer frame causality, paired with a reproducibility methodology and a declarative configuration manager built on top of it.
Formalized trust-boundary information leakage as a confidentiality invariant violation over compiler-visible ABI semantics. Programs can be syntactically correct, undefined-behavior free, and still violate system-level security invariants through object representation and padding behavior, a semantic class the type system cannot enforce.
Bootloader-stage mechanism to selectively disable hardware devices in the Linux device tree on a secure mobile platform, reducing attack surface before userspace initialization. A hardware-software boundary security problem: enforcing a source-level security policy across cross-compilation toolchains, U-Boot, and embedded Linux internals.
Building toward a measurement substrate for the Linux gaming graphics stack. Currently in the on-ramp: Vulkan fundamentals, reading the source of MangoHud and Gamescope, and standing up a non-NVIDIA machine, ahead of upstream contributions and a first frametime-capture prototype.
Built a formal model of trust-boundary information leakage grounded in C/C++ object representation semantics and ABI layout behavior. Implemented a complete Clang-Tidy static analysis module with CodeChecker integration, evaluated on open-source C libraries with manual validation of all emitted diagnostics. Zero false positives in real-world findings.
Built a bootloader-stage device-tree hardening mechanism for a secure mobile platform, reducing hardware attack surface before userspace initialization. Worked across cross-compilation toolchains, U-Boot, and embedded Linux internals; direct exposure to the semantic gap between source-level security policy and deployed binary behavior on real hardware.
Six years executing security authorization and compliance for mission-critical operational systems. NIST 800-53 controls, ATO packages, POA&M management, and incident coordination. TEMPEST enforcement per AFMANs, controlling electromagnetic emanation risks from hardware systems. COMSEC management including KMI operations and cryptographic material accountability.
I'm actively looking for software engineering and security engineering roles starting
August 2026, based in Phoenix or remote. My background is strongest in compiler security,
static analysis, and systems-level security work. I'm also early into Project Datum, a
long-term effort toward Linux graphics and driver work.
If you're working on problems in systems security, compiler infrastructure, or Linux
systems more broadly, I'd genuinely love to talk.