Founder | Cybersecurity Professional | AI-Assisted Development & Governance
Areas of Focus
Governance
AI Risk
Security Architecture
Compliance
Third-Party Risk
Supply Chain Security
“1. Failure is inevitable. 2. Compromise is the working assumption. 3. Resilience is layered, planned, rehearsed — success begins at concept.”
2
Projects
8
Certs
16
Milestones
794
Hours
PART I
About the Author
Solo founder and cybersecurity practitioner. My path has moved through different environments, but the constant has been building systems and understanding how they work. I design software and tools to solve real problems, then refine them through direct use. LabList started as a personal solution for tracking hands-on work and continues to evolve through that process.
I build web applications, think in systems, and treat security as foundational rather than optional. I enjoy analyzing risk and evaluating mitigations across supply chain, architecture, third-party trust boundaries, and the governance frameworks that hold them together. I'm targeting roles in GRC, AI governance, and compliance where this thinking compounds.
Always building. Always learning. Always improving.
Background
2026 — Founder — Dynamiq Learning LLC | LabList.io
Built secure SaaS apps. Designed IAM, session controls, input validation, and secure third-party API data handling to meet secure coding standards.
2023 — Water Treatment Operator — City of Dunedin
Operated SCADA and physical equipment to meet strict water quality regulations. Ran lab tests, monitored system data, and fixed equipment to prevent downtime.
2019 — Water Treatment Operator — Charleston Water System
Managed chemical treatment following EPA and OSHA rules. Analyzed water samples, prepared operations reports, and trained new hires on plant safety.
2017 — Sergeant (E-5) — United States Marine Corps
NCO managing operational risk and personnel compliance for 3rd LAR Battalion. Audited training programs and held an active Secret security clearance.
PART II
Entry-level technical roles keep asking for years of experience, which a flat resume can claim but not prove. The alternatives are a bland, easily forgotten GitHub repo, or buying a domain and building a static portfolio yourself. LabList streamlines that. It unifies projects, certifications, and labs in one professional portfolio that validates each resume point and stays easy to maintain, with some entries kept current automatically, so people can focus on what moves the needle, building real experience. LabList is the living proof of experience behind a resume. I built the full stack solo on Next.js and Supabase, from auth and Stripe billing to a guided writeup wizard and a defense-in-depth security model.
02/04/2026 — ongoing
A Claude Code plugin that turns senior DevSecOps judgment into enforceable rules grounded in primary sources. Every rule cites a sub-rule identifier from OWASP ASVS, NIST, ISO, MITRE, or an RFC. Built for developers using AI heavily who want their work to actually meet industry standards by default.
05/04/2026 — ongoing
PART III
| Certification | Issuer | Date | Status | |
|---|---|---|---|---|
CompTIA CySA+details... CompTIA06/28/2026active details... | ||||
SSCP (Associate)details... ISC212/04/2025active details... | ||||
CompTIA Security+details... CompTIA01/01/2025active details... | ||||
CompTIA Network+details... CompTIA10/01/2024active details... | ||||
CompTIA Project+details... CompTIA03/29/2026active details... | ||||
ITIL 4 Foundationdetails... PeopleCert04/01/2025active details... | ||||
PART IV
— Explore policies and frameworks vital for regulating cyber security in an organisation.
— Learn the steps and procedures of a red team engagement, including planning, frameworks, and documentation.
— Learn the important ethics and methodologies behind every pentest.
— CompTIA — active
— Covered material such as SAST and DAST tools for assessing API security. Understanding need for API inventory audits to determine what APIs are communicating and where. Determining if they are running outdated versions and if they are even still used. Discussed the need for secure API Gateways and the necessity of ensuring Authentication and Authorization when accessing APIs. While the course was short it provided actionable tips and general knowledge that was helpful and generated further interest for me to continue to pursue more information on API security.
— My view: AI will be largely responsible for the bulk of code going forward. I’ll defend that in a minute, but I should disclose something first. I’m not a software engineer. I have experience in languages like Python and SQL from classes I’ve taken, but fingers to keyboard coding isn’t my bread and butter. My domain is security, and software engineering itself isn’t my desired goal. I respect the work software engineers do and I commend their skills. That being said, I do see a shift happening....
PART V