Automation for AppSec at AWS (Part 2)
Context Is Infrastructure
In Part 1, I described how the SHINE team at AWS evolved from deterministic automations to CDK Blueprint Property Injection to the Agentic Security Engineer. I ended on a line that...
Context Is Infrastructure
In Part 1, I described how the SHINE team at AWS evolved from deterministic automations to CDK Blueprint Property Injection to the Agentic Security Engineer. I ended on a line that...
Why Skill Repos Struggle Where SaaS Succeeds
There is a pattern in security automation that repeats itself. Someone writes a smart script or skill that does something valuable, puts it in a shared repo, and schedules it to...
What Actually Changes When AI Writes More of Your Code
This post is something I wish someone had spelled out when I was getting my hands dirty again; how to do AI-Driven Development (AIDD) in a way that actually holds up. I’d recently...
And How We're Building the Future of AI-Powered Application Security
After nearly four years at AWS, I made the decision to leave in early December and join Pixee as a Distinguished Engineer, focusing on AI Security. I didn’t take it lightly. I’m...
Automation Before the AI
My time at AWS was spent working on application security at scale, most of that time building and leading the SHINE team (Security Hub of Innovation and Efficiency). Our mission to...
When AI Outpaced Security
I joined Amazon Web Services (AWS) in June 2022 as an Application Security Manager. My team was comprised of 11 high-judgment security engineers tasked with holding or raising the...