About
Career
Working in isolation. The through-line of my career has been security through process isolation — sandboxes, containers, build systems, mobile apps. Wherever we confine resources to prevent further privilege escalation, that is where I have spent my time. From containers running on firewalls to build systems running gVisor, seccomp filters blocking system calls to microVMs with hypervisor boundaries, securing LLM agents to breaking out of containers — I've found allowing untrusted things to execute to be an interesting problem space.
At Intrepidus Group that meant mobile application security. At NCC Group I started and led the container practice, working on containers and Kubernetes. At Snowflake I helped build remote code execution as-a-Service and, eventually, their fully managed Kubernetes cluster service. Chainguard was a chance to sharpen the same skills in build environments and agentic workloads, alongside some of the best people in the world on software supply chain security.
My talks live in this space too, from Docker to seccomp to microVMs, and now agentic isolation.
- NCC Group
- Snowflake
- Chainguard
- 1Password
Consulting
IOIOIO Security. My consulting practice is an opportunity to work with people building things and facing genuinely interesting problems. Usually that is sandbox or container work, or both at once — gVisor, or microVM runtimes for Kubernetes pods.
I'm always happy to meet and talk through the challenges you're facing, whether or not we end up working together on an engagement.
Community
Building a Rochester Security Community. Spending time in Chicago's security community and attending conferences like DEF CON, I wanted the same thing closer to home. What started as a few people looking for each other turned into three organizations — and a lot of the people who came through them have gone on to do remarkable things, using Rochester as the jumping-off point.
Security B-Sides Rochester
With a small group of friends we started Security B-Sides Rochester, watched it grow, and it is still running today. It began the year after BSidesLV — which makes it the second longest-running Security B-Sides in the world.
Interlock Rochester Hackerspace
Before BSidesROC there was the hackerspace. We ran it out of a warehouse in the Hungerford Building in downtown Rochester, and a lot of people passed through it. The events we held there produced some genuinely strange stories.
Rochester 2600
The 2600 chapter was my first step into a local hacker community. The meetup had been running for decades across various locations; I picked up the mantle and kept regular meetings going. It was never a formally organized event — just an opportunity for nerds to hang out with other nerds.