External Client SLA Delivery Platform

November 2025 - Present

PostgreSQLPower BISLASecurity

End-to-end project management of an SLA monitoring platform for an external logistics client. Designed a PostgreSQL data warehouse schema for SLA metrics aggregation, built Power BI dashboards for real-time KPI tracking across P1-P4 priority tiers, coordinated security pentests and vulnerability management, and orchestrated pilot deployment across distributed infrastructure. Managing weekly technical and steering committee meetings with cross-functional teams spanning operations, security, and data engineering.

45+
Work Items
P1-P4
SLA Tiers
3
Team Tracks

Tech: PostgreSQL, Power BI Desktop, Kubernetes, ITIL, Security Automation

ISO 27001 Information Security Certification

January 2026 - Present

ISO 27001Risk AnalysisComplianceSecurity

Leading the enterprise ISO 27001 certification initiative from foundation to audit readiness. Conducting risk analysis workshops and business impact assessments, implementing secrets management policies (A.5.17), hardening production access controls (A.8.32), and building the compliance documentation framework. Coordinating with stakeholders across infrastructure, development, and management to ensure organization-wide alignment on information security practices.

22+
Work Items
6
Active Workstreams
A.5-A.8
Control Domains

Tech: ISO 27001, Risk Assessment, BIA, ITIL, Secrets Management, Access Controls

Enterprise AI Integration Strategy

January 2026 - Present

AI/MLStrategyLLMChange Management

Steering the enterprise AI adoption strategy through a phased approach from experimentation to industrialization. Evaluating AI licensing models (frugal vs enterprise vendor), managing chatbot proof-of-concept pilots, conducting tool selection analysis, and building the decision framework for GO/NOGO gates. Coordinating with product, legal, and technical teams across a 4-phase roadmap spanning research, experimentation, validation, and deployment.

32+
Work Items
4
Phases
GO/NOGO
Decision Gates

Tech: AI/ML, LLM Platforms, Enterprise Architecture, Change Management, ROI Analysis

Multi-Client SQL Server Performance & Security Program

October 2024 - Present

SQL ServerPerformanceSecurityPowerShell

Multi-client SQL Server optimization program combining performance diagnostics and security hardening. Performance track: identifying bottlenecks, query tuning, and infrastructure right-sizing across production environments under load. Security track: automated certificate lifecycle management, connection string security scanning, and TLS enforcement. Developed PowerShell automation frameworks for repeatable diagnostics and remediation across 20+ server instances serving diverse client workloads.

20+
Server Instances
2
Tracks (Perf+Sec)
Auto
Cert Lifecycle

Tech: SQL Server, PowerShell, Certificate Management, TLS, Performance Tuning, Ola Hallengren

Enterprise Monitoring Infrastructure Architecture

February 2026 - Present

MonitoringArchitectureCMDBObservability

Designing the target monitoring architecture for a multi-site server fleet. Evaluating monitoring platforms (Centreon), alert management hubs (Keep/keephq), and CMDB solutions (Jira Assets) through structured POC deployments. Conducting live gap verification audits against current monitoring coverage, producing architecture decision records, and planning phased rollouts. Ensuring full-stack observability across physical servers, virtual infrastructure, and application layers.

3
POC Tracks
Multi-site
Fleet Scope
Full-stack
Observability

Tech: Centreon, Keep, Jira Assets, Prometheus, Grafana, Architecture Decision Records

Locksmith — Zero-Trust Secrets Management Bridge

March 2026 - Present

RustSecurityMCPSecrets

Building a zero-trust secrets management bridge between the Passbolt password manager and development toolchains. Rust-based CLI and MCP server with JWT authentication, OpenPGP decryption, and Aho-Corasick output scrubbing to prevent accidental secret leakage. Designed for seamless integration with AI coding assistants while enforcing strict secret isolation boundaries. Includes security hardening with zeroize memory handling, panic sanitization, and comprehensive test coverage.

Zero-trust
Architecture
MCP
AI Integration
Rust
Language

Tech: Rust, OpenPGP, JWT, Aho-Corasick, MCP Protocol, Passbolt API

Personal Portfolio & Blog Platform

October 2025 - December 2025

RustLeptosKubernetesSecurity

Built a full-stack portfolio website in Rust as a learning project, deliberately choosing the hard road over Next.js. Features include a theme system with 3 visual themes and 2 color modes (6 combinations), a build-time bilingual blog engine with syntax highlighting, SSR with WASM hydration for fast loads and SEO, and a contact form with honeypot traps and IP hashing. Security hardening includes CSP with nonces, HSTS, container lockdown (non-root, read-only filesystem, dropped capabilities), and Kubernetes network policies. Scored Grade A on external penetration testing. Deployed on K3s with Traefik ingress and Let's Encrypt certificates.

Grade A
Security Score
6
Theme Combos
SSR+WASM
Rendering

Tech: Rust, Leptos, Axum, PostgreSQL, K3s, Traefik, Podman, SCSS

Open Source

My public repositories on GitHub

Loading repositories...