Link 03 · Build◐ in progress
SLSA Build L3 pipeline
Fortune 10 healthcare company · 2026 – now · Tech lead- Problem
- Builds could not prove where an artifact came from or that nothing changed it on the way.
- Fix
- Leading a new GitHub Actions build pipeline that produces signed provenance on an isolated builder.
- Result
- In progress. Target: SLSA Build Level 3.
Link 01 · Source● shipped
GitHub & Actions platform
Fortune 10 healthcare company · 2026 – now · Tech lead- Problem
- Source control and CI for the whole company need one owner and one set of rules.
- Fix
- Lead the team that administers GitHub Enterprise (EMU) and GitHub Actions.
- Result
- One managed home for code and pipelines, with accounts tied to company identity.
Link 03 · Build● shipped
Security workflows for GitHub Actions
Fortune 10 healthcare company · 2024 – now · Main designer- Problem
- Each team wired up security scanners on its own, or not at all.
- Fix
- Designed and built most of the reusable workflows that run security tools and attest the results.
- Result
- Security scanning is part of the default path, not extra work.
Link 03 · Build● shipped
Security Orb
Fortune 10 healthcare company · 2022 – 2024 · Creator- Problem
- Teams on CircleCI had no shared way to run security tools and keep the results.
- Fix
- Built the Security Orb: reusable Python code that connects security tools and attests their results.
- Result
- CircleCI teams got the secure path without writing glue code.
Link 04 · Artifact● shipped
SBOM + cosign attestation
Fortune 10 healthcare company · 2022 – 2024- Problem
- Nobody could prove what was inside a container or which checks it passed.
- Fix
- Built a pipeline that generates an SBOM and attaches signed attestations to each image with cosign.
- Result
- Any image can be checked for its contents and scan results before deploy.
Link 02 · Deps● shipped
Distroless base images
Fortune 10 healthcare company · 2022 – 2024- Problem
- Full OS base images ship shells and packages apps never use, and each one brings CVEs.
- Fix
- Built and maintained distroless base images as the standard base for every developer in the company.
- Result
- Smaller images, a smaller attack surface, and one place to patch.
Link 05 · Deploy● shipped
Reusable CD to Argo CD
Fortune 10 healthcare company · 2024 – 2026- Problem
- Every team built its own path to Kubernetes.
- Fix
- Helped build and maintain reusable GitHub Actions CD workflows that hand off to Argo CD clusters on GKE.
- Result
- Deploys flow through git and one reviewed path.
Link 06 · Runtime● shipped
Service account rotation + IAP
Principal Financial Group · 2017 – 2020- Problem
- Long-lived service account keys, and apps protected only by network location.
- Fix
- Built a pipeline that rotates service accounts automatically and put Identity-Aware Proxy in front of apps.
- Result
- Keys expire on a schedule, and access checks who you are, not where you are.
Link 04 · Artifact● personal
My home server
Personal · ongoing- Problem
- Even a home server pulls new code from the internet every week.
- Fix
- k3s with Argo CD GitOps. Every image pinned by digest with a CI gate. Weekly Renovate and Trivy PRs. Cilium networking. Offsite backups.
- Result
- Nothing runs unless it is pinned, reviewed, and in git. Restore from offsite is tested.