I run talks and workshops on security and AI where your engineers put hands on their own stack and leave with the thing built. Fifteen years doing the work, still doing it, allergic to fear-selling.
I bring the structure, the failure modes, and the uncomfortable questions about what your controls actually prove.
The Power of DevSecOps in Web3 & Blockchain
OWASP GLOBAL APPSEC · DUBLIN 2023 · WATCH →
LASCON — INFRASTRUCTURE AS RCE
LOCKPICKING NIGHT — APPSEC TRAINING
Fifteen years building security programs inside companies that badly needed one — Web3 and blockchain, cloud at scale, and now AI systems that write and ship code. I run Asgard Security, and I co-host Relating to DevSecOps, where I've spent 80-something episodes asking practitioners what actually broke.
Off the clock: ESP32 boards and a soldering iron, a long-running Curse of Strahd campaign, singing, and strong opinions about headphones. I learn by building, which is the whole reason my workshops look the way they do.
Other people's microphones. Full episodes, no charge.
Developers, operators and security folks on where the handoffs break. Unsponsored, and it's going to stay that way.