Currently employed as a Security Engineer for AWS Cryptography.
Additionally, I work on open source software for the PHP community through Paragon Initiative Enterprises. A sample of open source security projects that are worth checking out include:
- CipherSweet: Searchable Encryption for PHP and Node.js
- Halite - a user-friendly PHP cryptography library powered by Libsodium
- Pharaoh - diff for executable PHP Archives
- Gossamer PKI (bringing secure updates to the PHP ecosystem)
I also publish blog posts about web development, application security, and other related topics. Some of my greatest hits:
- The 2018 Guide to Building Secure PHP Software (recommended by PHP: The Right Way)
- How to Safely Store Your Users' Passwords in 2016
- The difference between encryption and authentication, and why you want authenticated encryption
- Implementing a Login System in PHP, with a secure "Remember Me" feature
- Everything You Need to Know About Preventing Cross-Site Scripting Vulnerabilities in PHP
- The Easy and Definitive Guide to Preventing SQL Injection in PHP applications
- Choosing the Right Cryptography Library for your PHP Project: A Guide
My profile used to say:
My unrealistic goal is to be the first user with a gold badge in both Security and Encryption tags. (It's unrealistic simply because, odds are, others will beat me to it.)
...but that ended up happening on November 1, 2019.