Lead Software Engineer with 9+ years of experience building secure
CI/CD and container platforms at enterprise scale. Founding engineer and
technical owner of a multi-architecture base-image platform adopted by
700+ applications and used in 100,000+ image builds annually.
Specializes in secure-by-default developer infrastructure, software
supply chain security, automated vulnerability remediation, AWS, GitLab
CI/CD, and Go.
Skills
- Platform Engineering / Containers: Docker, Docker
Buildx, Kubernetes, OpenShift, Distroless Images, Multi-Arch Builds,
Helm, Sysbox, crane, skopeo
- Software Supply Chain / CI/CD: SLSA, Sigstore,
Cosign, SBOMs, Syft, Grype, GitLab CI/CD, GitHub Actions, JFrog
Artifactory, JFrog Evidence, Vulnerability Remediation
- Cloud / Infrastructure as Code: AWS, ECR, IAM, S3,
CloudWatch, Fargate, Terraform, OpenTofu, Ansible, VPC Networking
- Programming / Systems: Go, Python, Bash, Java,
JavaScript, TypeScript, Linux, Grafana, Prometheus, OpenSearch, JVM
Tuning, API Design
Experience
Lead
Software Engineer II, State Farm (Bloomington, IL /
Hybrid-Remote)
Apr 2024 - Present
Promoted to Lead Software Engineer II on the CI/CD platform team in
April 2024, then transitioned in early 2025 to become the founding
engineer and technical owner of the enterprise container image
platform.
- Beginning in Q1 2025, built and launched an enterprise container
image platform adopted by 700+ applications and used in 100,000+ image
builds annually.
- Designed and now operate a secure-by-default, multi-architecture
base-image ecosystem on Amazon Linux 2023, using Docker Buildx to
support Linux/amd64 and Linux/arm64 variants for Java/JVM,
JavaScript/TypeScript, Python, Go, and .NET across distroless and
development tiers.
- Implemented Cosign image signing, Docker Buildx provenance, and
JFrog Artifactory Evidence integration, advancing enterprise base-image
supply chain posture to SLSA Build Level 2.
- Automated nightly SBOM generation and vulnerability scanning with
Syft and Grype, reducing remediation time for fixable CVEs to under 24
hours after upstream patches became available.
- Developed Go runtime middleware for Kubernetes-aware JVM heap, CPU,
and garbage-collection tuning, plus an HMAC-secured telemetry proxy with
replay protection and Entra-authenticated forwarding that avoided
embedding credentials in images.
- Served as sole technical owner through the platform's first 18
months, setting its roadmap, adoption metrics, registry lifecycle and
promotion policies, support strategy, and stakeholder feedback
loops.
Lead
Software Engineer, State Farm (Bloomington, IL /
Hybrid-Remote)
Dec 2021 - Apr 2024
Technical lead for source control management and CI/CD platform
capabilities supporting 10,000+ engineers, with focus on pipeline
architecture, service resiliency, infrastructure as code, and developer
platform quality.
- Engineered shared GitLab Runner infrastructure with Sysbox-isolated
container builds; by 2022, the platform handled over half of State
Farm's CI/CD pipelines.
- Authored reusable Terraform modules for GitLab Runner fleet
deployment on AWS, including cross-account IAM credential patterns for
workloads running across isolated AWS accounts.
- Migrated CI/CD infrastructure from on-premises systems to AWS in
2023, adding autoscaling capacity for peak build loads.
- Built Grafana-backed CI/CD telemetry and led migrations from legacy
Jenkins infrastructure to shared GitLab patterns, including custom
solutions for complex workloads.
Software
Developer, State Farm (Bloomington, IL)
Jun 2018 - Dec 2021
Full-stack developer maintaining proprietary insurance product design
tools, backend security tooling, and platform modernization efforts.
- Built an internal dependency-scanning tool that surfaced vulnerable
packages and automated upgrade suggestions; the tool was adopted by the
application security team.
- Migrated applications from legacy WebSphere Application Server
infrastructure to Pivotal Cloud Foundry/Tanzu using Spring Boot,
PostgreSQL, RabbitMQ, REST APIs, Java IMS services, and IBM MQ.
IT/Systems Intern,
State Farm (Champaign, IL)
May 2017 - May 2018
- Developed a full-stack solution to support PCI DSS compliance audit
workflows.
- Assisted business partners with recovery-plan documentation for
business continuity.
Publications
Projects
Open-source declarative framework (project site) for
building hardened, minimal container images from reproducible Nix flakes
through a Go governance CLI. Produces development, slim, and distroless
runtime tiers and integrates keyless Sigstore/Cosign signing, SBOM
generation, provenance workflows, and Kyverno admission policies for
Kubernetes and OpenShift.
Nix | Go | Distroless | Kubernetes | OpenShift | Kyverno | Cosign
| SLSA | SBOM | Supply Chain Security
Published iOS app (App
Store) that removes metadata and redacts PII entirely on-device,
with no network calls, analytics, or third-party SDKs. Uses ImageIO,
Vision OCR, and face detection to identify 30 categories of sensitive
data across four risk tiers. Built in Swift/SwiftUI and released through
GitHub Actions and Fastlane, with provenance attestations covering the
public release IPA and a build workflow designed to support SLSA Build
Level 3.
Swift | SwiftUI | iOS | Vision | ImageIO | Privacy Engineering |
OCR | Fastlane | GitHub Actions | SLSA Level 3
Go CLI that generates Dockerfile and container image documentation
for platform teams, security reviews, and CI pipelines, with optional
Syft, Grype, and Dive integration for SBOM generation, vulnerability
scanning, and layer analysis.
Go | Docker | Podman | Syft | Grype | Dive | SBOM | Container
Security | CLI | GitHub Actions
Merged contribution to gitleaks adding support for appending
repository-specific and user-supplied configuration.
Go | Security | Secrets Detection | Open Source
Education
B.S.
in Agricultural and Consumer Economics - Finance in Agribusiness
(University of Illinois at Urbana-Champaign)
Aug 2014 - May 2018
Download PDF | Download Word Doc | Download
TXT | Download JSON