I find and responsibly disclose real security issues in AI/ML systems and production software. My work includes identifying unsafe deserialization (pickle/dill), remote code execution paths, path traversal, and authentication weaknesses in real, actively-used open-source libraries, with published proof-of-concept demonstrations and maintainer-accepted fixes.
Recent verified work includes discovering and responsibly disclosing a critical remote code execution issue requiring no login credentials in an open-source ML feature store, a trust and audit gap in a widely-used model serialization library, and a path traversal issue in an ML deployment tool, all independently verified with working proof-of-concept code and published as official GitHub Security Advisories.
Beyond security, I bring strong software engineering across Python, Java, JavaScript, TypeScript, C, C++, and SQL, with hands-on experience building LLM orchestration and multi-model routing infrastructure, AI model evaluation pipelines, and enterprise AI tooling.
What I offer:
- Static and dynamic security analysis of Python/ML codebases
- Deserialization security review (pickle, dill, joblib, custom serialization formats)
- API and authentication security review
- Proof-of-concept development and clear, actionable remediation guidance
- Clean technical writing and documentation of findings
I work carefully, verify every finding against the latest release before reporting, and communicate clearly throughout. Available for one-off audits, ongoing security review retainers, or general software engineering work.