- a small writing room.

Notes.

Half essay, half marginalia. Mostly about AI agents, security systems, the boring details that make products actually work, and what I've learned by writing it down. New entries land here when they're ready.

start here if you're hiring -

a short path through my work.

A curated reading path for recruiters, founders, CISOs, and engineering leaders who would like to understand how I approach AI-native cybersecurity, agentic SOC, SecOps platforms, and hands-on engineering leadership.

01Agentic SOC product strategy for founders who need the real version.Agentic SOC strategy is not 'AI replaces analysts.' The real strategy is choosing a painful workflow, proving trust, and earning automation step by step.02The AI cybersecurity founding CTO memo I would want to read.A founding CTO in AI cybersecurity has to build the product, the trust system, the engineering culture, and the risk posture at the same time.03What I would build as Head of AI Security Platform.If I owned an AI security platform, I would build around evidence, controlled agency, analyst workflows, reliability, trust, and a team that can ship without losing judgment.04From AI security demo to production: the checklist I use.AI security demos are easy to like. Production systems need evidence, permissions, evals, observability, rollout discipline, and a plan for being wrong.05AI security leadership interview questions I would actually ask.A practical interview loop for finding AI security leaders who can build systems, lead teams, reason about risk, and ship products analysts can trust.06The agentic SOC architecture scorecard.An agentic SOC platform should be judged by the control system around the model, not by the confidence of the demo.07How I would evaluate an AI security engineering leader.The fastest way to hire an AI security engineering leader is to stop interviewing only for management polish.08My 90-day plan for leading an AI security engineering team.The fastest way to evaluate an AI security engineering leader is to ask what they would change in the first 90 days.09What I mean by builder-leader in cybersecurity engineering.Builder-leader is the shortest phrase I have for the kind of cybersecurity engineering work I want to do next.
filed by mood →

showing 42 published notes

Note №.0422026 · 07 · 23
Cost engineering for AI security agents.

The useful cost metric for an AI security agent is not cost per token. It is cost per defensible security outcome.

≈ 8 min-- tokens are a line item, loops are a design flawaisecurityinfrastructureplatformleadership
Note №.0402026 · 07 · 19
Migrating a SOC without breaking the analysts.

A SOC migration is an operating-model change disguised as a platform project.

≈ 8 min-- migrations fail in the handoffssecuritysecopsleadershipplatforminfrastructure
Note №.0392026 · 07 · 17
Build versus buy for agentic SOC capabilities.

The useful build-versus-buy question is not whether to buy an AI SOC. It is which layers create advantage and which create maintenance.

≈ 8 min-- own the differentiation, rent the undifferentiatedaisecuritysecopsleadershipopinions
Note №.0382026 · 07 · 15
Building an evaluation dataset for AI SOC agents.

An AI SOC evaluation set should represent the decisions analysts face, not merely the questions models answer well.

≈ 9 min-- production failures deserve permanent test casesaisecuritysecopsdatabuilding
Note №.0372026 · 07 · 13
Multi-tenant architecture for AI security platforms.

In AI security SaaS, tenant isolation has to survive retrieval, memory, tools, traces, and every cache between them.

≈ 9 min-- tenant context all the way downsecurityaiplatforminfrastructurebuilding
Note №.0362026 · 07 · 11
Red teaming autonomous security agents.

A security agent becomes dangerous through the combination of untrusted context, trusted tools, and borrowed authority.

≈ 9 min-- test the authority, not only the answeraisecurityagentssecopsbuilding
Note №.0342026 · 07 · 07
Measuring whether an AI SOC is actually working.

An AI SOC should be measured by better security decisions and calmer operations, not by how many model calls it makes.

≈ 9 min-- measure the workflow, not the theatreaisecuritysecopsleadershipplatform
Note №.0332026 · 06 · 25
Agentic SOC product strategy for founders who need the real version.

Agentic SOC strategy is not 'AI replaces analysts.' The real strategy is choosing a painful workflow, proving trust, and earning automation step by step.

≈ 11 min-- because the TAM slide is not the productaisecuritysecopsagentsstartupproductleadership
Note №.0322026 · 06 · 25
The AI cybersecurity founding CTO memo I would want to read.

A founding CTO in AI cybersecurity has to build the product, the trust system, the engineering culture, and the risk posture at the same time.

≈ 10 min-- or the startup brief that filters out the wrong chaoscareerleadershipsecurityaistartupbuilding
Note №.0312026 · 06 · 25
What I would build as Head of AI Security Platform.

If I owned an AI security platform, I would build around evidence, controlled agency, analyst workflows, reliability, trust, and a team that can ship without losing judgment.

≈ 12 min-- or the job description I keep accidentally writing for myselfcareerleadershipsecurityaiplatformbuilding
Note №.0302026 · 06 · 25
From AI security demo to production: the checklist I use.

AI security demos are easy to like. Production systems need evidence, permissions, evals, observability, rollout discipline, and a plan for being wrong.

≈ 11 min-- because the demo is where risk politely wears a blazeraisecuritysecopsplatformbuildingleadership
Note №.0292026 · 06 · 25
AI security leadership interview questions I would actually ask.

A practical interview loop for finding AI security leaders who can build systems, lead teams, reason about risk, and ship products analysts can trust.

≈ 14 min-- for recruiters, founders, CISOs, and anyone allergic to vague leadership interviewscareerleadershipsecurityaisecopsbuildinghiring
Note №.0282026 · 06 · 25
The agentic SOC architecture scorecard.

An agentic SOC platform should be judged by the control system around the model, not by the confidence of the demo.

≈ 13 min-- or twelve questions before the demo gets dangerousaisecuritysecopsagentsplatformbuilding
Note №.0272026 · 06 · 25
How I would evaluate an AI security engineering leader.

The fastest way to hire an AI security engineering leader is to stop interviewing only for management polish.

≈ 12 min-- or the interview loop I wish more teams usedcareerleadershipsecurityaisecopsbuilding
Note №.0252026 · 06 · 25
The control plane for SecOps agents.

The difference between useful SecOps agents and dangerous SecOps agents is the control plane around them.

≈ 11 min-- or one agent kept on a leashaisecuritysecopsagentsplatform
Note №.0242026 · 06 · 25
The evidence layer in AI security platforms.

AI security platforms will not earn analyst trust by sounding fluent. They will earn trust by showing evidence.

≈ 10 min-- or one summary that can defend itselfaisecuritysecopsplatformbuilding
Note №.0222026 · 06 · 07
Engineering reliable AI security agents.

If an AI security agent becomes part of the SOC workflow, it needs reliability engineering like any other production system.

≈ 12 min-- or one agent outage noticed before the analyst doesaisecuritysecopsreliabilityagents
Note №.0212026 · 06 · 07
Designing an AI threat intelligence pipeline.

Threat intelligence pipelines fail when they treat intelligence as a feed problem. The hard part is turning sources into evidence, context, and decisions.

≈ 12 min-- or one IOC pile turned into contextaisecuritythreat-intelsecopsbuilding
Note №.0202026 · 06 · 07
Building a SOC knowledge graph for agentic investigations.

Agentic SOC systems need memory, but not the soft kind. They need a structured graph of entities, evidence, relationships, and decisions.

≈ 12 min-- or one less tab spiralaisecuritysecopsagentsknowledge-graph
Note №.0192026 · 06 · 05
Agentic incident response playbooks.

Agentic incident response is not autonomous panic. It is structured delegation inside a response system that preserves evidence and keeps humans in control.

≈ 13 min-- or one incident bridge with fewer tabsaisecuritysecopsincident-responseagents
Note №.0182026 · 06 · 05
The identity-first AI SOC.

Modern intrusions often look like normal users doing abnormal things. That makes identity the center of the AI-native SOC.

≈ 13 min-- or one valid account caught earlyaisecuritysecopsidentitybuilding
Note №.0172026 · 06 · 05
How to evaluate AI SOC agents before production.

An AI SOC agent should not graduate to production because it gave three impressive demos. It should graduate because it survived evaluation.

≈ 12 min-- or one confident hallucination caughtaisecuritysecopsagentsevaluation
Note №.0162026 · 06 · 05
Detection engineering for an AI-native SOC.

AI can help write detections, but detection engineering is still an evidence discipline, not a prompt trick.

≈ 13 min-- or one noisy rule retiredaisecuritysecopsdetectionbuilding
Note №.0152026 · 06 · 05
Securing agentic AI tools for the SOC.

Agentic AI in the SOC becomes dangerous when tools are treated like plugins instead of production security interfaces.

≈ 12 min-- or one overpowered tool avoidedaisecuritysecopsagentsbuilding
Note №.0142026 · 06 · 05
Agentic AI in the SOC: the builder-leader talk security teams need now.

The best AI cybersecurity talk right now is not about replacing analysts. It is about rebuilding the SOC around evidence, workflow, trust, and controlled agentic systems, from someone who can build and lead the work.

≈ 15 min-- or one panel question answered earlyaisecuritysecopsagentsspeakingbuildingleadership
Note №.0122026 · 05 · 26
Building a dark web exposure intelligence agent.

Dark web exposure work is not just searching shady indexes. It is entity resolution, evidence handling, identity risk, source confidence, privacy discipline, and response orchestration.

≈ 16 min - or one leaked credential panic avoidedaisecuritythreat-intelagents
Note №.0112026 · 05 · 23
Engineering AI workflow systems with Langflow.

Langflow makes AI workflow structure visible. Production engineering begins with deciding which responsibilities belong outside the graph.

≈ 9 min - or three conditional edgesaiagentsinfrastructureworkflow
Note №.0102026 · 05 · 26
Building deep research systems for cybersecurity intelligence.

Security investigations are not search problems. They are evidence problems. Deep research systems need retrieval, correlation, memory, provenance, and a refusal to invent confidence.

≈ 18 min - or one analyst with a calmer inboxaisecurityresearchthreat-intel
Note №.0072026 · 05 · 12
The interesting boundary around the model.

Most "AI product" work is really tool design, approval-flow design, and observability. The model just sits in the middle, doing the easy part. A short essay on what actually makes these systems good.

≈ 6 min - or one slow espressoaiagentssecuritybuildingopinions
Note №.0062026 · 04 · 28
Search, on top of object storage.

What you give up, what you get back, where the math actually works out, and the strange small joy of a query plan that ends in s3.GetObject.

≈ 9 min - or two cups of filter coffeeinfrastructuresearchbuilding
Note №.0052026 · 03 · 15
Why "agentic" is quietly becoming useless.

A useful word is losing its meaning because it is being used for everything. The repair starts with verbs and authority.

≈ 7 min - or one elevator argumentaiopinionsagents
Note №.0042026 · 02 · 22
Triage is a UX problem, mostly.

SOC triage starts with the decision surface: what gets grouped, what gets hidden, what needs evidence, and when a human should be asked.

≈ 8 min - or the time for an Argo rolloutaisecuritysocopinions
Note №.0032026 · 01 · 18
What I learned writing my first MCP server.

The protocol is small. The interesting design decisions are not: descriptions, schemas, permissions, errors, and when an agent should not use a tool.

≈ 9 min - or a long ssh reconnectaiagentsinfrastructurebuilding
Note №.0022025 · 12 · 03
Reading the cap table like an offer letter.

Vesting, strike price, dilution, preferences, and exercise terms change what the equity number on an offer actually means.

≈ 8 min - or one careful teaopinionscareer
Note №.0012025 · 10 · 09
Demos are easy. Tuesdays are hard.

The gap between a thing that works in the room and a thing that works in a customer's hands on Tuesday morning is where most engineering taste lives.

≈ 8 min - or a slow K8s pod restartinfrastructurebuildingopinions
that's everything pinned to the wall, for now.
new notes show up whenever they're ready.