My name is Sammy 👋
I’m a security engineer and architect with 12+ years building and securing infrastructure in complex, global environments. I started my career in the U.S. Army 🛡️, and that foundation still shapes how I work: I engineer first and architect always. I don’t just design security systems; I build, test, and operate them before recommending them broadly.
I currently work at PwC as a Manager, Global - Solution Security Architect, focused on workforce and endpoint security at large scale (hundreds of thousands of users and devices across many countries). Earlier on that same path I was a Global Endpoint Security Engineer, where I deepened hands-on work in host hardening, DLP and data security, identity, threat modeling, and Zero Trust.
My primary focus right now is AI security as a forward deployed architect (FDA). I sit with the problem end to end: how teams actually use coding agents and GenAI tooling, through threat modeling and control design, then shipping, validating, and hardening what lands on real endpoints. I own the thread from idea to production, not just the slide deck.
That work sits alongside the broader endpoint platform lifecycle (MDM/UEM and compliance), Zero Trust and secure access patterns, and agentic AI governance on the desktop: how coding agents and MCP-style tooling can ship safely without turning every laptop into an ungoverned risk. I care about controls that raise the bar without freezing the business.
Before security, I worked in IT operations and support: networking, systems, and real-world firefighting. That background keeps architecture grounded. Pretty diagrams only matter if they survive production and help people do their jobs.
My military service as a U.S. Army Veteran taught leadership under stress, clear decisions with incomplete information, and how trust and team discipline reduce risk when it counts. I bring that same bias to action into cybersecurity.
I write regularly on my blog ✍️ about endpoint and macOS hardening, Zero Trust, detection, supply-chain risk, and securing AI coding agents. I also authored material in Secure Bash for macOS on secure agentic AI development: sandboxing, MCP/skill supply-chain vetting, and practical guardrails that feed back into how I think about enterprise endpoint AI.
I maintain a homelab 💻 to break and rebuild things, and I contribute to open source 🌍, including policy-driven, audited access for AI tools (MCP SSH Orchestrator), secure-by-default cloud APIs (DOaaS), and data-security test tooling (Synthetic Data Hub). More is on the projects 💻 page.
Coding is a personal craft as much as a day job: Bash, Python, and small systems that automate the boring parts so people can focus on judgment.
At the core, I believe security is not only technology. It’s people, trust, and collaboration. Durable systems come from understanding human behavior and building a culture where everyone can play a part in protection.
