Long-form write-ups on security, AI, and career growth, published here so they're easy to link, fork, and reuse.
This repo is a public collection of the notes and guides I write for my own reference and share with the community. Most of it comes out of day-to-day work running AppSec/Product Security teams, plus some general AI-usage and career material that doesn't fit anywhere else. Everything here is free to reuse under the license below: take what's useful, adapt it, pass it on.
- AI Security Checklist: P0-to-P3 prioritized controls for standing up an AI security program, from governance to LLM/RAG/agent-specific safeguards.
- Security Tooling Landscape: a categorized map of the InfoSec vendor/tool landscape (GRC, SIEM, SOAR, and more).
- Threat Modeling: system design + threat model write-ups, each covering architecture, trust boundaries, DFDs, and a threat table:
- Password Manager
- P2P Payment App
- Cloud File Storage Service
- Multi-Tenant SaaS Isolation Model
- Three-Tier Architecture
- GitLab-Style SaaS (Multi-Tier)
- Threat Modeling a Local AI Box (Mac Studio Edition)
- Building a Password Manager the Way a Real Team Would
- Threat Modeling: The Complete Guide, From Zero to Expert
- The Complete Claude Workflow Guide: subscriptions, tools, agents, MCP, and automation, covering the Claude ecosystem from beginner to expert.
- Token Efficiency Guide: a practitioner's guide to using Claude efficiently, covering what drives token/cost and how to cut waste.
- AI Terminology Reference for Software Engineering and Security: AI/ML terms for engineers and security folks, each with what problem it solves and when it's the wrong choice.
- Cloud & App Architecture Glossary: cloud and app architecture concepts (microservices, serverless, and more), what they are, why they exist, and when to skip them.
- Product Security Definitions: core product security vocabulary, scoped and framed for engineers new to the discipline.
- Software Terms to Learn: plain-language explainers for common software engineering terms, with everyday analogies.
- AppSec-ProdSec-DevSecOps Learning Path: a practical roadmap for breaking into AppSec/ProdSec/DevSecOps, from someone who hires for it.
- Product Security Competency Pathway: what's expected at each career level, laid out dimension by dimension.
- Managing Up: what managing up actually means and why visibility matters more than people think.
- Spotting AI-Generated Text: patterns and tells for identifying AI-written content, kept current as models evolve.
- LinkedIn Algorithm 2026 Guide: a deep dive into how the LinkedIn algorithm works and what changed going into 2026.
Everything in this repo is licensed under Creative Commons Attribution-ShareAlike 4.0 International (CC BY-SA 4.0). In short: you're free to share and adapt this material for any purpose, including commercially, as long as you give appropriate credit and license any derivatives under the same terms.