Seven years securing federal cloud environments across Azure, Kubernetes, and AKS. My research turns that operational work into machine-readable assurance evidence, so compliance stops being a claim and becomes an artifact you can verify.
Every framework and schema in this body of work came out of running the systems first, then finding the missing piece.
Audits rely on tickets, spreadsheets, and deployment logs. Those records fragment, drift, and cannot be independently verified after the fact.
Remediation emits a signed, timestamped record bound to the specific vulnerability it closed. Proof is generated by the work, not reconstructed afterward.
Authorization evidence packages that a machine can validate, so continuous assurance replaces the annual scramble for screenshots.
Patents, papers, and credentials, each with its identifier and a link to the primary source. Verify any of it.
A practical assurance playbook for federal suppliers and critical infrastructure. Written for the engineers, compliance leads, and DevSecOps practitioners who operate these systems every day, not for the people who write policy about them.
The book is the practical extension of the patents and papers listed above. It covers evidence object schemas, exposure mapping, KEV-driven prioritization, and the validation workflows that turn a patch cycle into an audit-ready record.
Doctoral work in applied artificial intelligence, in progress, extends this into automated evidence generation.
Schemas and validation workflows that make an authorization package something software can check.
NIST SSDF and patch controls compiled into executable policy that emits its own proof.
Wrapping legacy federal microservices in ephemeral PQC sidecars without rewriting them.
Prioritizing by observed exploitation and blast radius instead of nominal CVSS score.
The research is downstream of the operations. Roles below are the source material.