I build AI agent systems for production, with security at the core. I started
orchestrating agents in production at IriusRisk, where my team shipped a
multi-agent simulation platform for secure-by-design engineering before agents
became the industry's favorite word, and today I run my own fleet of coordinated
agents, each one isolated in its own container, because an agent is also an
attack surface.
Behind that there are twenty-five years of building software, most of them
spent defending companies from attackers: Mimecast, IriusRisk, and now bunny.net.
What I work on
I work with teams building secure, enterprise-grade agent and LLM
systems: agent security and orchestration, threat modeling for AI,
guardrails and gateways, multi-tenant architecture, evaluation-first delivery,
and AI governance / EU AI Act readiness.
The security philosophy is contain, not prevent. Prompt injection is unsolved
at the model layer, acknowledged by the major labs, so the discipline is identity,
isolation, least privilege, and human-in-the-loop, built so that a tricked agent
has nothing to exfiltrate, no way to escalate, and no action it can take alone.
bunny.net · Head of AI
Strategy, platform, and security-by-design for AI features on edge
infrastructure serving a large share of the internet.
2024-25
IriusRisk · Head of AI
Built the AI team and platform from zero, and shipped agent systems to
production when that was still rare: Jeff (guided threat modeling, onboarding
from hours to minutes), Bex (risk triage inside Jira), and ASH, a
secure-by-design twin-simulation multi-agent platform. EU AI Act-compliant
delivery.
2023
DTEK.ai · Head of AI
Vision-based automation and generative AI for retail. Multi-modal
ecosystem pairing vision models with a custom AI assistant.
2017-23
Mimecast · Big Data Specialist, Staff, then Principal ML Engineer
Core ML infrastructure serving 2.5B+ predictions a day across ten services.
Production computer vision, LLM-based phishing categorization, observability and
cost governance.
2014-17
Zed · Lead ML / Big Data Architect
Distributed graph engine processing billions of nodes (Spark/MapReduce).
EU-funded R&D in graph machine learning.
I write Disrupted AI,
a newsletter on secure and auditable enterprise LLM systems: threat modeling,
agent security, guardrails, gateways, multi-tenant architecture, and evals.