Skip to main content

Alexander
North

Founder | Cybersecurity Professional | AI-Assisted Development & Governance

Areas of Focus

Governance

AI Risk

Security Architecture

Compliance

Third-Party Risk

Supply Chain Security

1. Failure is inevitable. 2. Compromise is the working assumption. 3. Resilience is layered, planned, rehearsed — success begins at concept.

2

Projects

8

Certs

16

Milestones

794

Hours

PART I

ABOUT

About the Author

Solo founder and cybersecurity practitioner. My path has moved through different environments, but the constant has been building systems and understanding how they work. I design software and tools to solve real problems, then refine them through direct use. LabList started as a personal solution for tracking hands-on work and continues to evolve through that process.

I build web applications, think in systems, and treat security as foundational rather than optional. I enjoy analyzing risk and evaluating mitigations across supply chain, architecture, third-party trust boundaries, and the governance frameworks that hold them together. I'm targeting roles in GRC, AI governance, and compliance where this thinking compounds.

Always building. Always learning. Always improving.

Background

2026Founder — Dynamiq Learning LLC | LabList.io

Built secure SaaS apps. Designed IAM, session controls, input validation, and secure third-party API data handling to meet secure coding standards.

2023Water Treatment Operator — City of Dunedin

Operated SCADA and physical equipment to meet strict water quality regulations. Ran lab tests, monitored system data, and fixed equipment to prevent downtime.

2019Water Treatment Operator — Charleston Water System

Managed chemical treatment following EPA and OSHA rules. Analyzed water samples, prepared operations reports, and trained new hires on plant safety.

2017Sergeant (E-5) — United States Marine Corps

NCO managing operational risk and personnel compliance for 3rd LAR Battalion. Audited training programs and held an active Secret security clearance.

PART II

PROJECTS

Featured

LabList: a living technical portfolio platform

read more...

Entry-level technical roles keep asking for years of experience, which a flat resume can claim but not prove. The alternatives are a bland, easily forgotten GitHub repo, or buying a domain and building a static portfolio yourself. LabList streamlines that. It unifies projects, certifications, and labs in one professional portfolio that validates each resume point and stays easy to maintain, with some entries kept current automatically, so people can focus on what moves the needle, building real experience. LabList is the living proof of experience behind a resume. I built the full stack solo on Next.js and Supabase, from auth and Stripe billing to a guided writeup wizard and a defense-in-depth security model.

Next.jsReactTailwind CSSPostgreSQLSupabaseVercelStripeEdge Functions+7 more

02/04/2026ongoing

TGF — The Governance Framework for AI-Assisted Development

read more...

A Claude Code plugin that turns senior DevSecOps judgment into enforceable rules grounded in primary sources. Every rule cites a sub-rule identifier from OWASP ASVS, NIST, ISO, MITRE, or an RFC. Built for developers using AI heavily who want their work to actually meet industry standards by default.

Claude Code plugin platformHooks for enforcementMarkdown language for skillsJSONGitOWASP ASVSNIST SP 800-39NIST SP 800-53+6 more

05/04/2026ongoing

PART III

CERTIFICATIONS

CertificationIssuerDateStatus
CompTIA CySA+details...
CompTIA06/28/2026active

Credential

Hidden

Status

active

Skills

SecOpsThreat DetectionIncident ResponseVulnerability ManagementPatch ManagementRisk Management
SSCP (Associate)details...
ISC212/04/2025active

Credential

Hidden

Status

active

Skills

Risk ManagementGovernanceAccess ControlIdentity and Access Management (IAM)Security OperationsIncident Response
CompTIA Security+details...
CompTIA01/01/2025active

Credential

Hidden

Status

active

Skills

Risk ManagementGovernanceComplianceThird-Party Risk ManagementSecurity ArchitectureZero Trust
CompTIA Network+details...
CompTIA10/01/2024active

Credential

Hidden

Status

active

Skills

Network ArchitectureNetwork SecurityTCP/IPDNSRouting and SwitchingWireless Networking
CompTIA Project+details...
CompTIA03/29/2026active

Credential

Hidden

Status

active

Skills

Project ManagementRisk ManagementStakeholder ManagementChange ControlVendor ManagementProject Lifecycle
ITIL 4 Foundationdetails...
PeopleCert04/01/2025active

Credential

Hidden

Status

active

Skills

Service ManagementIT GovernanceRisk ManagementChange ManagementIncident ManagementProblem Management

PART IV

ACTIVITY LOG

Governance & Regulation - TryHackMe
·read more...

Explore policies and frameworks vital for regulating cyber security in an organisation.

Type

ctf

Duration

1h

Date

08/05/2026

Skills

Red Team Engagements - TryHackMe
·read more...

Learn the steps and procedures of a red team engagement, including planning, frameworks, and documentation.

Type

ctf

Duration

1h

Date

07/31/2026

Skills

Pentesting Fundamentals - TryHackMe
·read more...

Learn the important ethics and methodologies behind every pentest.

Type

ctf

Duration

1h

Date

07/31/2026

Skills

CompTIA CySA+
·read more...

CompTIA — active

Semgrep - API Security Mini Course
·read more...

Covered material such as SAST and DAST tools for assessing API security. Understanding need for API inventory audits to determine what APIs are communicating and where. Determining if they are running outdated versions and if they are even still used. Discussed the need for secure API Gateways and the necessity of ensuring Authentication and Authorization when accessing APIs. While the course was short it provided actionable tips and general knowledge that was helpful and generated further interest for me to continue to pursue more information on API security.

Type

learning

Duration

1h

Date

06/11/2026

Skills

API Security, DAST, SAST

alexlearnstech313/tgf — 31 commitsAudit skills/code-quality/ — WS4 Target 14 (Build Step 5, Commit 16/22) — closes Build Step 5; Audit skills/discovery/ — WS4 Target 11 (Build Step 4, Commit 13/22) — closes Build Step 4; Audit skills/project-management/ — WS4 Target 10 (Build Step 4, Commit 12/22)read more...
Type

dev

Duration

4h

Date

06/07/2026

Skills

When the vibes are high, but the guardrails are low.
·read more...

My view: AI will be largely responsible for the bulk of code going forward. I’ll defend that in a minute, but I should disclose something first. I’m not a software engineer. I have experience in languages like Python and SQL from classes I’ve taken, but fingers to keyboard coding isn’t my bread and butter. My domain is security, and software engineering itself isn’t my desired goal. I respect the work software engineers do and I commend their skills. That being said, I do see a shift happening....

Type

writeup

Duration

Date

06/03/2026

Skills

alexlearnstech313/tgf — 8 commitsAudit skills/security-input-validation/ — WS4 Target 4 (Build Step 3, Commit 6/22) — closes Build Step 3; Amend CLAUDE.md §2 with communication discipline + file research-security hook bug; Audit skills/security-output-encoding/ — WS4 Target 3 (Build Step 3, Commit 5/22)read more...
Type

dev

Duration

6h

Date

05/28/2026

Skills

alexlearnstech313/tgf — 11 commitsOperationalize security-auditor agent + coordinate boundary discipline (WS3 Build Step 3, Commit 4/6); Operationalize red-team agent + apply smoke-test refinements (WS3 Build Step 4, Commit 5/6); Freshen status docs to reflect Phase 6 pause + framework-hardening progressread more...
Type

dev

Duration

Date

05/26/2026

Skills

alexlearnstech313/tgf — 4 commitsAdd Workstream 2 plan for WORKFLOW-V2 methodology grounding; Update planning docs to reflect Workstream 1 completion; Register 12 framework sources for WORKFLOW-V2 researchread more...
Type

dev

Duration

Date

05/24/2026

Skills

PART V

CONTRIBUTIONS

JanFebMarAprMayJunJulAugSepOctNovDec
Projects
Certs
CTFs
Learning
Labs
Writeups
Events
DEV
Multiple