From SaaS products at a public cybersecurity company to open-source tools used in universities and SOCs — a sampling of the work I've led, owned, or built with my own hands.
Incubated, proved, and led product, GTM, and business development for the launch of Rapid7's Cyber GRC solution — unifying Security Operations and GRC in a single platform to improve cross-functional efficiency and align security outcomes with compliance, and created an audit partner program. Now generally available — Rapid7 is the first major security operations platform to unite SecOps and GRC. Announced via the Cyber GRC Early Access Program and a HITRUST assurance partnership.





Founded and built The Cyber Toolchain — an LLM-native intelligence system for the security tooling market, surfacing the security tools worth your attention. It monitors 835 open-source and commercial tools for new capabilities, summarizes what's genuinely new, and publishes a daily newsletter, a paid analytics product, and a public dataset. I designed, built, and operate all of it solo with agentic coding tools — over 500,000 lines of tested Python across eight repositories — including the evaluation layer underneath it: LLM-as-judge output scoring, gold-set precision gates that block publication below threshold, and structural grounding guards so the system never publishes a claim it cannot point at.
Led the product & GTM launch of Rapid7's flagship exposure-management offering, aligned to Gartner's CTEM framework. It became the company's dominant land-and-expand VM offering and earned a Leader position in the inaugural Exposure Assessment Platform Magic Quadrant (2025).

2024 launch of Rapid7's attack-surface management product — the only solution of its time to unify internal (CAASM) and external (EASM) ASM with risk-based vulnerability data, giving the best visibility of assets and identities. It consolidated tools customers previously bought across multiple vendors. Built on Rapid7's acquisition of Noetic Cyber.
Owned the success of Rapid7's SOAR product line — 2000+ customers and $20M+ ARR within two years. Ran the P&L for a ~100-person org spanning engineering, design, product, and operations.

Founding security member of Komand, an early-stage Boston cybersecurity startup acquired by Rapid7 in 2017. Security leader, Field CTO, integration developer that built the secure platform and automation use-cases, sold the technology onsite, and contributed to the product itself.

Embedded investigative and response tools across multiple Rapid7 products to drive SOAR adoption and surface platform value in-context, meeting users where they already worked.

The community marketplace where customers discover and share Insight product extensions, integrations, and workflows. Built to help users integrate their technology ecosystem and achieve better security outcomes across hundreds of tools.

A community forum and gamified engagement layer where users ask questions, share use cases, and get the latest product news. Designed an XP-based leaderboard to reward posts, solutions, and contributions — driving participation and customer-led support.

Practical tooling I authored over the years — security training environments, monitoring plugins, and network analysis utilities used across many organizations.
Isolated, Scalable & Lightweight Environment for Training. Used to teach Linux & security tooling at universities and for-profits; co-authored a peer-reviewed paper at XSEDE.
A widely-forked collection of Nagios monitoring plugins covering a broad range of infrastructure checks.
Searches log files for known network indicators of compromise against malware reputation lists. Installs on any GNU/Linux host.
Vagrant files and related tooling for spinning up reproducible security and lab environments.
A collection of Bro/Zeek network-security-monitoring scripts written during NSM team work.
Calculates PPS, BPS, and percentage of line-rate from Linux kernel statistics via procfs — debug network performance without extra packages.

A book chapter built from my research and conference talks on cybersecurity training — detailing Linux containers and how to use them for training and development environments. Published by Syngress (Elsevier).

An article in the Spring 2015 issue (Volume 32, Number 1) of the long-running hacker magazine.

Proceedings of XSEDE, July 2015 — St. Louis, MO
Including Network Traffic Analysis at Marshall University's cybersecurity conference
Dig into the experience behind these launches, or reach out about advisory work.