Automation for AppSec at AWS (Part 2)
Context Is Infrastructure
In Part 1, I described how the SHINE team at AWS evolved from deterministic automations to CDK Blueprint Property Injection to the Agentic Security Engineer. I ended on a line that...
Context Is Infrastructure
In Part 1, I described how the SHINE team at AWS evolved from deterministic automations to CDK Blueprint Property Injection to the Agentic Security Engineer. I ended on a line that...
KC to CHI on an Amtrak Full of Hackers
This weekend, my buddy Mike Kunz and I drove from Omaha to Kansas City on July 17th to board a train. Not to go anywhere in particular. To attend a conference. A conference on a...
Why Skill Repos Struggle Where SaaS Succeeds
There is a pattern in security automation that repeats itself. Someone writes a smart script or skill that does something valuable, puts it in a shared repo, and schedules it to...
What Actually Changes When AI Writes More of Your Code
This post is something I wish someone had spelled out when I was getting my hands dirty again; how to do AI-Driven Development (AIDD) in a way that actually holds up. I’d recently...
And How We're Building the Future of AI-Powered Application Security
After nearly four years at AWS, I made the decision to leave in early December and join Pixee as a Distinguished Engineer, focusing on AI Security. I didn’t take it lightly. I’m...
Automation Before the AI
My time at AWS was spent working on application security at scale, most of that time building and leading the SHINE team (Security Hub of Innovation and Efficiency). Our mission to...
I’ve been using an Eight Sleep Pod 3 for a while now, and while I love the autopilot temperature control and sleep tracking features, I’ve always been frustrated by the cloud...
My Conference Review
I spent a couple of excellent days at BruCON in Belgium. It’s a conference that blends deep technical content with a relaxed friendly hacker vibe all fueled by local Belgium beer,...
When AI Outpaced Security
I joined Amazon Web Services (AWS) in June 2022 as an Application Security Manager. My team was comprised of 11 high-judgment security engineers tasked with holding or raising the...
The Sequel
Welcome. This is my second attempt at creating and maintaining a blog. My first go at blogging was way back when I was trying to break into the cybersecurity field. Like so many in...