Most security people don't understand how modern AI systems actually fail. Most AI engineers don't think like an attacker. I work in the small overlap — finding the vulnerabilities that only show up once you understand both sides.
I've spent my career breaking systems on purpose so they don't break in production: real threat models, real exploits, defenses built to survive contact with an adversary. Now I'm pointing that same instinct at agentic and LLM-powered systems, because that's where the next generation of vulnerabilities is already showing up — and most teams haven't started looking yet.
If you're shipping AI features and want someone who finds what breaks them before your users or your attackers do, that's the work I want to be doing.
Where I spend my curiosity outside of shipped work — the boundary between how systems think and how they get broken.



