Regulated AI
NDA
Financial-Sector AI Security
Full-time AI red team engineering
Practical AI security work in a regulated banking environment, including assessment of customer-facing AI systems, attack scenario development, control validation, and security enablement for engineering teams.
Client: ████████Banking
Architecture
NDA
Agentic AI Security Advisory
Architecture review & operating concept
Security advisory for enterprise agentic AI stacks involving coding agents, MCP-style tool integrations, containerized environments, model gateways, threat modeling, and BSI/OWASP-aligned control mapping.
Client: ████████Enterprise IT
Product
NDA
AI Coding Platform Assessment
AI development tools
Security assessment of an AI-powered development platform with IDE integration, multi-tenant architecture, agent workflows, and code-assistance features.
Client: ████████Dev platform
Agents
NDA
Tool-Using Agent Assessment
CRM, email, calendar & workflow tools
Assessment of autonomous agent workflows with business-tool integrations, focusing on prompt injection, tool misuse, data exposure, permission boundaries, and unsafe delegation.
Client: ████████Enterprise SaaS
Disclosure
Public
HashiCorp Nomad Sandbox Escape
CVE-2026-14891 · Docker task driver
Container-to-host sandbox escape in HashiCorp Nomad's Docker driver, found with an AI-augmented code-review harness and confirmed with a working exploit. Reported, fixed in Nomad 2.0.4, and credited in HCSEC-2026-21. The same principle drives enterprise AI security assurance: findings only matter when they become reproducible evidence, severity, remediation, and retest.
Read the disclosure ↗
Open Source
Public
Microsoft PyRIT
AI red teaming framework
Top contributor to Microsoft PyRIT, helping improve practical tooling for AI red teaming, adversarial testing, and campaign automation.
github.com/microsoft/PyRIT ↗
Standards
Public
OWASP GenAI Security
Guides and methodology
Contributor to multiple OWASP GenAI Security Project guides, including red teaming, agentic threats, incident response, and securing agentic applications.
OWASP GenAI Security Project
Training
Public
Enterprise Enablement
Agentic AI red teaming training
Author-led training format for technical teams working with LLM applications, coding agents, MCP, RAG, tool integrations, and agentic workflows.
Cohorts from October 2026