Infrastructure Security & AI Systems Engineer
Building trustworthy systems at the intersection of backup & DR, security tooling, and local AI governance. 13+ years of hands-on infrastructure depth — no quota, no vendor motion.
I treat backup infrastructure as ground-truth memory and last-resort truth stores. This perspective shapes how I build security tooling and local AI systems that are auditable, resilient, and resistant to hallucination or data leakage by design.
The most valuable work happens at the intersections — not inside any single domain. Enforcement-layer design, not prompt-layer design.
An interactive view of the domains I operate across and the bridges between them.
Offline-first RAG Agent
Production-grade local AI gateway with LangGraph-enforced security policy, SHA-256 soul governance, triple-gated external fallback, and a hybrid ChromaDB/BM25 retrieval pipeline. Topology-enforced RAG-first — not prompt-based.
Security Tooling / Detection
PowerShell + YARA pipeline detecting ransomware C2 configs, .onion links, and payment portal signatures within Veeam Secure Restore contexts — applied threat detection from the DR side.
Backup / DR Auditing
PowerShell audit suite validating Veeam VBR job health, immutability posture, and repo capacity. Produces executive-ready HTML reports. Prevents backup failures during SCCM patch windows via proxy integration.
RAG Knowledge Corpus
Structured markdown corpus and RAG ingestion pipeline feeding PsyClaw — versioned, offline-first, and designed for deterministic local retrieval with prompt-injection defenses at the loader level.
High-fit, non-quota, enterprise or vendor-of-record positions where the work is solving real problems.
Ready to build auditable, secure, and trustworthy systems together?