What I work on
A tour of the technical areas I've spent the most time on. Each section is grounded in shipping systems, patents, and press coverage where available.
IP and domain reputation at internet scale
At Intel and McAfee I owned the data pipelines, classifiers, and threat-hunting practice behind global IP and domain reputation feeds. In steady state that meant ~30 million IP blocks and ~200,000 domain blocks published every year, feeding firewalls, email gateways, and endpoint products worldwide. Those numbers didn't come from passively ingesting third-party lists — they came from active threat hunting: pivoting on telemetry signals, chasing infrastructure across protocols, and building the classifiers that turned each hunt into durable, published protection. The engineering challenge was less about volume and more about signal quality: making sure the blocks we published were correct enough that customer help desks did not drown in false-positive tickets.
A big part of the work was replacing external reputation feeds with internally generated intelligence, which cut third-party data costs while giving us more control over precision and coverage. Patent US 11,743,276 grew out of this line of work: combining cross-protocol signals into a single reputation score that is more robust to any one channel being poisoned.
Botnet analysis and takedowns
Much of my early classifier work targeted the largest email-sending botnets of the era — Rustock, Grum, Cutwail, Kelihos, and their descendants. I contributed to takedown-adjacent analysis, wrote the classifiers that recognized their traffic in the wild, and spoke to the press regularly as those campaigns collapsed and reorganized.
The lesson that has stuck with me: takedowns are a punctuation mark in a much longer story. Real, durable protection comes from telemetry pipelines that keep pace with attackers as they migrate infrastructure, not from any single legal or technical action.
Machine-learning classifiers for malicious traffic
Building ML classifiers that hold up in production security is a different discipline from building them in a notebook. Attackers actively adapt to your model; feature drift is adversarial, not just statistical. I spent years doing feature engineering for messaging, connection, and domain classifiers — and, importantly, building the internal tooling that let researchers iterate on those features quickly against fresh telemetry.
Patent US 11,689,550 covers one line of that work: analyzing malicious network traffic in a way that generalizes across attack families rather than overfitting to any single campaign. The internal research portal I built at McAfee — unifying disparate data sources behind one query interface — is what made that kind of iteration practical for the team.
Mobile threat intelligence
At Zimperium the work shifts to mobile: on-device detection and cloud-side analytics for iOS and Android threats, from malicious apps and phishing to network-layer attacks. I led the data, edge, and application-analysis engineering teams that turn on-device telemetry into intelligence customers can actually operationalize — including a full uplift of the datacenter footprint from physical Rackspace infrastructure to virtualized Oracle, and a new generation of edge delivery systems that get threat intelligence out to customer consoles in near real time.
I chair the Principal Engineering Committee, which is where we align long-term technical priorities across the org, and I'm the executive-level escalation contact for threat analysis on strategic accounts.
Messaging abuse: spam, phishing, and email fraud
Spam and phishing are where I cut my teeth. From CipherTrust and Secure Computing through McAfee, I've written and maintained anti-spam classifiers, spearphishing detection heuristics, and connection-reputation systems that fed the email-security products of that era. I designed and produced the complete anti-spam configuration for the IronMail appliance, ran zero-day fixes, and trained engineers on the backend systems and UNIX internals that kept it running.
This is also where the public-relations side of my career started. Editors and reporters need someone who can explain a new phishing wave, a spoofed-brand campaign, or a botnet flare-up in plain language on deadline. I've done that a lot.
Talking to the press, customers, and government
For seven of my nine years on the McAfee PR team I sat on the steering committee. I've delivered keynote talks on future threat trends, taught training courses at conferences, presented on thirteen-plus panels, and been quoted in hundreds of press interviews from CNN, ABC News, and the LA Times through IEEE, security-industry trades, and international outlets.
The through-line: security only becomes protective when it's communicated well. A great classifier that no one understands is a lawsuit waiting to happen; a well-explained one earns the trust that keeps customers deploying it. See the public relations page for a curated selection.