Security built into the pipeline, not bolted on after the breach.
Security is not a feature you add at the end — it is a property of how you design, build and ship software. The teams that stay out of incident channels bake it into the workflow: threat modeling before code, pipelines that fail closed, and auth that is boring because it is correct. I treat security as an engineering discipline with measurable controls, including in regulated enterprise systems, backed by CSA CCSK and CCZT.
Articles in this hub
5 articles
IntermediateUser-Level Permission Controls for MCP Tool Access with an Enterprise MCP Gateway
MCP gives your AI agents real power — reading files, calling APIs, moving money. But who decides which user or agent can reach which tool? Here is how an enterprise MCP gateway turns that question into a policy you can actually enforce, from the gateway down to every laptop.
Read article
IntermediateBuild Your Own CSPM on GCP: Security Command Center vs Open Source
You do not need a six-figure platform to get Cloud Security Posture Management on GCP. Here is how to build CSPM two ways — the free built-in Security Command Center and a DIY open-source stack — and when each one wins.
Read article
AdvancedKill Your Service Account Keys: Workload Identity Federation on GCP in 2026
Long-lived service account keys are a breach waiting to happen. A hands-on 2026 guide to Workload Identity Federation on GCP: how the keyless token exchange works, wiring GitHub Actions with zero secrets, the attribute-condition trap that opens your project to any repo, and migrating off keys without downtime.
Read article
IntermediateThe First 24 Hours with Security Command Center: What Nobody Tells You
What really happens when you open Google Security Command Center for the first time: 764 findings, single-digit compliance, and a calm plan to fix the right things first.
Read article
IntermediateStop Storing JWTs in LocalStorage: Cookie Auth for SPAs in 2026
A practical 2026 guide to moving JWT authentication out of LocalStorage and into HTTP-only cookies with CSRF protection for SPA, SSR, upload, WebSocket, gateway, and mobile scenarios.
Read article
FAQ
What is your security background?
Are you available to hire?
How do we start working together?
Want security that ships with you?
From auth design to hardened CI/CD and supply-chain defense, I help teams build security into the workflow instead of patching it after an incident.
See security services →