As a student, timelines of my work experiences are a bit confusing to read. This is meant to clarify.
Experience
Cyber Skyline · Software Security Engineer
May 2023 – present
- Developed, deployed, and maintained cybersecurity challenges across a variety of cybersecurity topics.
- Redesigned system for deployment of docker containers across multiple hosts for competitions.
- Conducted a security audit of new CISA infrastructure.
Cisco Systems · Security Research Engineer Intern
Summers 2023 – 2025
- Product security evaluation with Cisco’s Advanced Security Initiatives Group (ASIG) of a flagship software solution; responsible for 30 of ~50 team findings, 3 critical. (2023)
- Extended university research on Large Language Models (LLMs) applied to dynamic execution. (2024)
- Implemented university research on LLM-assisted JavaScript deobfuscation. (2025)
- Product security evaluation with ASIG of a new cloud-based product offering; responsible for 15 of ~25 team findings, 1 critical. (2025)
Research
Google · Wolfpack Security and Privacy Research Lab (WSPR) · Research Assistant
August 2023 – present
- Developed a distributed fuzzer for fingerprinting/fuzzing Chromium optional features. (2023)
- Collaborated with Google researchers on the usage of LLMs for static code analysis. (2024 – 2025)
- Led a 25 person team building a framework for how attackers manipulate and bypass automated LLM code review. (2025)
- Participated in pre-public launch security testing of a OpenAI flagship chat model (GPT 4.x). (2025)
- Led a research project studying differentials between URL parsing technologies. (2026-present)
U.S. Navy · Naval Research Laboratory (NRL) · Technical Intern
2023
- Researched modeling techniques, focusing on applications of LLMs in data analysis.
NASA · University of Alabama in Huntsville (UAH) · Researcher
2020 – 2022
- Designed, built, and programmed a computing research project flown to the International Space Station.
- Designed and programmed high altitude balloon experiments studying microelectronic reliability in spaceflight, including systems for reliable, secure communication.
Projects
- DEO — a custom JavaScript deobfuscator combining static and dynamic analysis, built to support LLM assisted deobfuscation research.
- Distributed Chromium fuzzer — a distributed fuzzing and fingerprinting system exercising Chromium features at scale. (2023 – 2024)
- HackPack CTF platform — the challenge infrastructure behind the 2024 and 2025 HackPack CTF AI/LLM security competitions.
Education
North Carolina State University
August 2022 – May 2027
- B.S. Computer Science | 4.0/4.0 | May 2026
- M.S. Computer Science | 4.0/4.0 | May 2027
- Park Scholarship: full merit based academic scholarship, 40 selected from 2,200 worldwide.
- University Honors Program.
Independent Security Work
- 25+ published CVEs across Cisco, Open WebUI, Jenkins, WikiMedia, and the Linux Foundation, including multiple critical findings. Further findings remain under NDA.
- 100+ private bug bounty contracts; published findings against the U.S. Department of Defense (one Critical) and IBM.
- U.S. DoD Hacker of the Month. (May 2024)
- President, NC State HackPack security club. (2024 – present)
- Created mini lectures for 40+ members and wrote grants for a traveling competition CTF team.
- 1st BSidesROC (2026), 1st BSidesRDU (2023), 2nd DukeCTF (2025), 2nd BSidesRDU (2025), 3rd BSides NYC (2024).
- Created and ran HackPack CTF 2024 and 2025 (LLM/AI security competitions).
Security Coursework
- Computer Security (CSC 405), Operating Systems (501), Compiler Theory (CSC 512), Software Security (515), Computer Networks (CSC 570), Internet Protocols (CSC 573), Network Security (574), Advanced Network Security (774)
- IT & Data Assurance I/II (CEH, Security+); Linux Essentials, System Administration, Network Applications (Linux+, RHCSA, RHCE); Digital Forensics (GCFE)
Skills | Keywords
Languages — Python, JavaScript, TypeScript, C, Java, Go, Bash
LLM / AI / ML ops — Ollama, OpenWebUI, llama.cpp, LangChain, CUDA
DevOps — Docker, Docker Compose, Celery, GitHub Actions, Podman, Kubernetes, Ansible
Web security — Burp Suite, Postman, amass, gobuster, nuclei, subfinder
Network security — Wireshark, netcat, arpspoof, mitmproxy, scapy
Static / dynamic analysis — Semgrep, Binary Ninja, Ghidra, AFL++, Autorize, CodeQL