Machine learning · AI security · Threat intelligence

Building production AI for real-world security problems.

I build machine learning systems at the intersection of AI, cybersecurity, threat intelligence, and production engineering.

Machine LearningAI SecurityThreat IntelligenceProduction AI

Beyond the model

The useful work begins where a model meets the constraints of a real system.

My path started in cybersecurity and threat analysis, where repetitive classification problems created an opening for machine learning. Since then, I have built detection pipelines, threat-intelligence workflows, retrieval systems, and AI-powered knowledge experiences designed to operate—not just demonstrate.

Read the career story

Areas of expertise

Security context. Statistical judgment. Production discipline.

I work across the full path from imperfect data and feature design to deployment, operational feedback, and durable knowledge systems.

01 / 04

Applied machine learning

Practical model selection, sparse language features, structured signals, evaluation, and iteration around real operating costs.

02 / 04

AI security

Phishing detection, threat intelligence, adversarial context, explainable decisions, and privacy-aware AI systems.

03 / 04

Production pipelines

Scheduled data workflows, validation, deduplication, artifact management, monitoring, and reliability on AWS.

04 / 04

Knowledge systems

Retrieval-augmented generation, semantic search, graph data models, metadata, and grounded product experiences.

Selected work

Systems built for evidence, context, and operation.

Three case studies spanning security classification, recurring intelligence pipelines, and enterprise retrieval.

Detection engineering / Production ML

Production Phishing Detection Pipeline

A multi-stage machine learning pipeline for detecting phishing domains in DNS traffic using character-level language features, domain metadata, threat intelligence, and an ensemble of classifiers.

Pythonscikit-learnCharacter 3-gram TF-IDFRandom Forest
Read case study

Professional highlights

A career shaped by security operations and applied AI.

Current work

Production phishing detection

Leading machine learning pipeline development for DNS security on AWS.

Generative AI

Enterprise RAG delivery

Led services for a production learning assistant, semantic search, and knowledge retrieval.

Security foundation

Cisco Talos threat intelligence

Built models, automation, analytics, and intelligence data systems for cybersecurity operations.

Field notes

Writing from the space between research and operations.

Drafts in progress on phishing features, production threat detection, and what AI security can learn from threat intelligence.

What AI Security Teams Can Learn From Traditional Threat IntelligenceIn the lab
Why Character N-Grams Still Work for Phishing DetectionIn the lab
Taking a Threat-Detection Model From Notebook to Hourly ProductionIn the lab

For hiring teams

The one-minute version.

A concise overview of target roles, production experience, security depth, technical stack, and the projects most relevant to senior applied AI work.

Start a conversation

Building something where AI has to hold up in the real world?

I’m interested in senior work across applied machine learning, AI security, threat intelligence, and production AI systems.