I'm drawn to the badly-defined problems that emerge when technology outpaces the frameworks meant to govern it — privacy when data governance was still uncharted, cloud security as enterprise adoption introduced new classes of risk, and now AI as autonomous agents create challenges no existing playbook covers.
Professional Experience
Tech Lead, Cloud AI Security
March 2024 – Present
- Lead the security architecture of all GCP Vertex and Agent Engine products, spanning model inference, agentic platforms, and supporting services, shipping product security features (e.g. Agent Identity in Agent Engine) and hardening that limited blast radius of potential attacks.
- Partner across Google Cloud product and engineering teams to embed security requirements early in the design of new AI capabilities, ensuring secure-by-default behaviors at the platform level
- Shape Google's internal posture on agentic AI risk, translating novel threat models into actionable security controls for builders of agent-based products
- Lead vulnerability management and security incident response for Cloud AI. Drove FedRAMP compliance for vulnerability management processes and led response to 10+ security incidents — spanning VRP reports and internal findings — each requiring complex mitigation projects.
Tech Lead and Manager, Cloud Hybrid Platforms and AlphabetCloud
September 2019 – February 2024
- Designed and enforced security guardrails for Alphabet entities and acquisitions onboarding to Google Cloud, spanning dozens of companies and thousands of engineers operating under Google's data security and privacy standards
- Drove secure adoption of BigQuery and GKE for critical internal workloads, building compliance frameworks and security tooling that made high-stakes data processing possible within Google's policy boundaries
- Built the foundational platform infrastructure securing public-facing products and major data analysis pipelines; at peak scale, the system underpinned 60%+ of all internal GKE usage (tens of thousands of VMs) and housed ~30% of Google's total BigQuery data
- Grew and led a team of 10 engineers; set technical direction and drove architectural decisions for a broader organization of 30+ engineers across Cloud Hybrid Platforms
Tech Lead and Manager, Privacy and Data Governance
September 2013 – August 2019
- Built large-scale automated systems to detect datasets stored or accessed without adequate privacy controls, scanning across Google's storage infrastructure to surface risks at a scale no manual process could reach
- Led Google's engineering response to GDPR for key product areas, translating regulatory requirements into technical controls and data governance standards adopted across the company's product portfolio
- Defined data lifecycle and access policies for sensitive datasets, partnering with legal, policy, and product teams to operationalize privacy-by-design principles across engineering orgs
Projects
Agent Engine CLI
A simple CLI to manage GCP Agent Engine resources. Streamlines the workflow for deploying and managing AI agents on Google Cloud Platform.
PythonSchoopet AI
An intelligent agent designed to help you never forget important things. Built with modern AI agent frameworks.
PythonADK Samples
A collection of sample agents built with Google's Agent Development Kit (ADK). Demonstrates best practices for agent development.
PythonSelected Publications
-
VeriGuard: Enhancing LLM Agent Safety via Verified Code Generation
arXiv, 2025
-
Distributed Security Policy Conformance Best Paper
Computers & Security, 2013 / IFIP SEC 2011
-
A Middleware for Assured Clouds
Journal of Internet Services and Applications, 2012