leeky.sh

About

leeky

Ten years in tech, eight of them in information security. I can build full-stack applications and I can break them, and that combination is the whole point. Fuzzing, tooling, and AI are where I spend my time.

Most of what I publish here comes out of the same loop: build a system, learn where its assumptions leak, then build the thing that finds those leaks automatically. The web3 scanner exists because I have written the kind of contract it audits. The PR review pipeline exists because manual review does not survive contact with a thousand repositories.

I am looking for large scope, real autonomy, a fast environment, and leadership that actually wants to invest in AI.

Focus

  • Application security
  • Threat modeling
  • Penetration testing
  • Red teaming
  • AI & LLM systems
  • Fuzzing
  • Software development

Certifications

OSCE · OSCP · CASP+ · CySA+ · Security+ · Network+ · Linux+

Experience

  1. 2025 — present

    Founding Engineer · AI security startup

    • AI security research
    • Vulnerability discovery alongside frontier AI and aerospace teams
    • Engineering automated AI security systems
  2. 2024 — 2025

    Sr. Red Team Engineer · Major cloud provider

    • Led red team engagements end to end, from scoping through report
    • Drove AI adoption inside the offensive tooling stack
    • Cloud and container security, with a Kubernetes focus
    • Spearheaded a CI/CD initiative that retired entire vulnerability classes
  3. 2022 — 2024

    Lead Privacy Security Engineer · Large social platform

    • First hire on the Privacy Red Team; built and led a team of five
    • Started the company's first privacy bug bounty program
    • Offensive testing and threat modeling across web, mobile, and internal infra
  4. 2020 — 2022

    Sr. Application Security Engineer · Enterprise networking company

    • SAST/DAST into CI/CD with custom middleware
    • Automated cloud vulnerability discovery and triage across 60+ AWS accounts
    • Led the FedRAMP initiative; Qualys across 600+ servers
  5. 2017 — 2020

    Penetration Tester · National retailer

    • Red team exercises against corporate and retail networks
    • Purple team training, code review, bug bounty management
    • Built a security dashboard and custom offensive tooling
  6. 2017

    Security / Support Engineer · Crypto custody platform

    • Ran the bug bounty program
    • Incident handling and ELK monitoring for exchange customers
  7. 2015 — 2017

    Sr. Developer Support Engineer · Developer tooling company

    • Built a log analyzer for automated issue analysis
    • Traffic and log analysis tooling
  8. 2014 — 2015

    Hardware Operations Engineer · Hyperscale datacenter operator

    • Datacenter operations in standard and non-standard infrastructure