application security · devsecops · ai security
Security that ships with the product.
I make security usable — layered controls, automated pipelines and risk-based decisions, embedded into delivery instead of bolted on. Guardrails on the road, not a roadblock across it. Below are eight anonymised case studies of how I actually work.
method
How I work
Every engagement follows the same spine — the flowcharts on each case study page show this applied to real projects, phase by phase, step by step.
Assess
Map the real risk surface — code, dependencies, infrastructure, data and workflows.
Design
Proportionate, layered controls anchored to OWASP ASVS — testable, not aspirational.
Embed
Automation inside the tools developers already use — guardrails, not roadblocks.
Operate
Ownership, SLAs, evidence and metrics — security that runs day-to-day without chasing.
selected work
Eight case studies, capability level
Engagements are anonymised at capability level — no client, employer or system names. Open any card for the problem, the approach and an interactive flowchart of the engagement.
Enterprise AppSec Rollout: Snyk Platform, Automation & Jira Integration
A Snyk SAST/SCA platform built from the ground up — phased repo onboarding, tuned triage, automated Jira integration and pull-request feedback inside developer workflow.
View case study →DevSecOps Operating Model & Pipeline Security Design
A DevSecOps process designed from scratch — existing tools tied into one coherent, measurable operating model with ASVS-anchored, testable controls.
View case study →AI Security: Guardrails for Coding Agents, LLMs & MCP
Guardrails for coding agents, LLMs and MCP integrations — AI adoption requirements that survive vendor conversations and procurement scrutiny.
View case study →Enterprise CRM Platform Security Hardening
Phased hardening of a CRM platform holding sensitive personal data — event monitoring, field audit trails, encryption and non-production data protection.
View case study →Cloud-Native API Security Architecture
A layered security model for a public-facing, API-driven platform — from edge and gateway controls to identity, segmentation and evidence-based assurance.
View case study →Secure Credential & Secret Lifecycle Design
Credential sharing and rotation reframed as a governed lifecycle — central storage, clear ownership and a path to automated, auditable rotation.
View case study →Security Monitoring & Detection Design
Detection engineering that a SOC can act on — prioritised use cases across APIs, identity, cloud services and configuration drift.
View case study →Secure Adoption of Developer & API Tools
Tool selection as a governance decision — a proportionate adoption path and business case balancing usability, control strength, effort and cost.
View case study →about
Application security specialist
I work where software engineering, cloud platforms and governance meet: defining secure designs, embedding controls into delivery workflows, improving visibility of vulnerabilities, and helping leaders make proportionate risk decisions.
I can challenge a token design, shape a pipeline control, define a vulnerability operating model — and then explain the investment case to leadership in language that supports a decision.
Core areas
- Application & API security
- DevSecOps
- SAST/SCA platforms
- Vulnerability management
- Cloud security architecture
- Secrets management
- Security monitoring
- AI security & governance