// credentials & journey

From the Field to the Boardroom

I help security and engineering leaders design systems that are secure by architecture, not by accident. What follows is what 5 years in offensive security and 2.5 years in product security have taught me about threat modeling, secure design, AI security, and privacy engineering — on the way to becoming a Security Architect.

Why does this content exist?

The goal is to close the gap between offensive security experience, product security reality, and enterprise architecture practice — publishing real, technically credible breakdowns of threat modeling, secure-by-design engineering, AI security, and privacy compliance, so that both the security community and the people who hire security leaders can see exactly how I think. The content itself is the portfolio.

Longer term, the objective is to become a recognized Security Architect — and eventually an AI Security Architect or Fractional CISO — by building a visible, technically rigorous body of work that a CTO or VP of Engineering encounters before the resume ever reaches them. The interview should start from established credibility, not a cold introduction.

What actually makes this different?

Most people writing about security architecture have never broken anything. I've spent 5 years finding real vulnerabilities as an offensive security professional and 2.5 years living with the consequences and trade-offs of product security inside a real engineering org — a combination that's rarer than it should be among people writing about this field.

That's layered on top of a genuine, visible certification journey (CISSP, CCSP, CSSLP, CIPT) and hands-on fluency with the newest frameworks — MAESTRO for agentic AI threat modeling, LINDDUN for privacy, AAISM for AI security management. This isn't theoretical content. It's a documented, provable trajectory that a CTO or VP can evaluate before ever picking up the phone.

What won't change, regardless of what's trending

Every framework, standard, or certification claim gets stated correctly — credibility with a technical audience is the entire asset here, and it's not worth spending on engagement bait. Posts explain the reasoning and trade-offs behind a decision, not just the conclusion, because that's what a hiring manager is actually screening for. Real frameworks, checklists, and lessons get given away freely, not withheld behind a "DM me" paywall — the content itself is the proof of competence. Junior and aspiring security professionals are a core audience, not an afterthought. And certification struggles, failed exam attempts, and real career pivots get shared openly, because that's more useful to the next person walking a similar path than a polished highlight reel would be.

— GK

2026—now
Security Architect, AI Security

Building governance frameworks for AI/ML systems at CISO-level strategy.

2025
Product Security — Threat Modeling

Led enterprise-wide threat modeling initiatives across product security.

2021
Product Security Engineer & Vulnerability Management

Embedded secure-by-design practices and ran vulnerability management across product teams.

2019
Penetration Tester, Offensive Security

Found the gaps defenders miss — and learned how attackers actually think.

Certifications
AWS Certified Security - Specialty HELD
CTMP — Certified Threat Modeling Professional HELD
CISSP IN PROGRESS

Eight-plus years spans offensive security, product security engineering and enterprise architecture — now focused on AI security governance and CISO-level risk strategy.