Break systems responsibly
Access-control testing, network investigation, protocol analysis, and disclosure work grounded in reproducible evidence.
Opening record…
Security researcher / builder
Security research, applied AI, and tools people actually use.
Profile / operating range
The through-line is practical: understand the system deeply enough to expose what is fragile, then make something stronger.
I'm a Computer Science student at the University of Notre Dame and a published security researcher. My work spans vulnerability disclosure, network security, developer tools, applied AI, and systems that meet the physical world.
Right now, I'm contributing to engineering at Lila Sciences. I also co-founded Phoenix Fire Labs to develop autonomous wildfire monitoring with computer vision and drone integration.
Outside software, I volunteer on Skid Row, play club volleyball, and make 3D animated films. Those are not side notes: they are where technical work becomes human, visual, and accountable.
Access-control testing, network investigation, protocol analysis, and disclosure work grounded in reproducible evidence.
Open-source and product engineering across Python, TypeScript, Next.js, MCP, SQLite, and applied AI.
From BLE packets and macOS databases to cloud infrastructure, computer vision, and human-facing product decisions.
Python / TypeScript / React / Next.js / MCP / Network security / Vulnerability research / Nmap / Kubernetes / Terraform / SQLite / Computer vision
Work / selected engagements
Security, scientific infrastructure, robotics, health data, and applied AI—work shaped by systems that have to function outside a demo.
Engineering Intern
Contributing to engineering at an autonomous science company combining AI, robotics, and experimental infrastructure.
Co-Founder
Developing Prometheus, an autonomous wildfire monitoring system using computer vision and drone integration for real-time detection and tracking.
Information Security Intern
Ran scoped Nmap and packet-capture investigations, diagnosed production connectivity across VPNs and VLANs, and contributed to Kubernetes and Terraform workflows.
Project Intern
Standardized healthcare eligibility data, delivered a CRM-integrated back-end platform, and designed the operator-facing experience.
AI Software Developer
Built an intelligent assistant connecting company data across Freshdesk and Salesforce for fast, conversational access.
Builds / public artifacts
Tools and products are strongest when someone else can install them, inspect them, or rely on them.
Autonomous systems
Computer vision and drone integration for continuous wildfire detection, tracking, and faster situational awareness.
Phoenix Fire Labs · Co-Founder
Developer utility
A Go CLI and interactive TUI that turns codebases into syntax-highlighted context for LLMs, documentation, and code review.
Homebrew + native packages · automated releases
Network tooling
A dependency-free packet-capture explorer that defensively decodes PCAP and PCAPNG files into terminal answers and deterministic structured output.
Dependency-free runtime · cross-platform CI
Network systems
A Rust screen-sharing system that transmits changed regions through direct QUIC, relay-backed NAT traversal, native viewers, and zero-install browser viewing.
Direct QUIC + relay NAT traversal
Security research
A steganography tool that hides encrypted payloads inside emoji variation selectors, exploring a covert channel in Unicode.
Encrypted Unicode covert channel
Live product
An AI-assisted men's health training platform built around structured exercises, progression, and confidence.
staminatimer.com · production
Developer utility
Tracks Claude Code rate-limit resets and sends timely SMS reminders before access returns.
Live service · Twilio notifications
Computer vision
Digitizes student IDs for Apple Wallet and Google Pay using Gemini Vision and mobile pass tooling.
Senior capstone · deployed prototype
Research / responsible disclosure
Two published access-control vulnerabilities in Splashin, documented with reproducible impact and disclosed responsibly.
High severity
The backend did not enforce the advertised 600-second update restriction. Direct API calls could retrieve current location data at arbitrary intervals.
Critical severity
A premium-only location request lacked server-side authorization, allowing free users to force immediate target updates through push notifications.
Training / context
Formal study at Notre Dame, industry security training, and a visual practice shaped by four years of animation.
2025 — 2029 / Notre Dame, Indiana
BA, Computer Science
Coursework and campus work spanning cybersecurity, artificial intelligence, political systems, and practical engineering. Active in Cyber Club, UAV Club, Wall Street Club, and club volleyball.
Verified security training
Visual work / recognition
Contact / open channel
Security research, applied AI, developer tooling, or something that crosses those boundaries—send the useful context and I’ll respond directly.