Epochs I and II · Network engineering, online platform · 1995–2003
You can’t secure what you can’t see
I started as a network engineer at Xavier University, writing utilities to manage a fleet of about 6,000 workstations while finishing a BS in Computer Science. Around 2000 I managed the team building an online B2B commodities brokerage that did about $120M a year and was acquired by IDSA. In the early 2000s I was pulled more and more toward security, given my background in network architecture, controls and security monitoring.
Epoch III · Network security · 2003–2014
Make the network explain itself
Bro, now Zeek, treated network monitoring as a programmable platform rather than a signature box. I helped raise awareness of the platform by teaching hundreds of free workshops. I helped deploy Bro across dozens of major enterprises and started to see that across every organization, every regulatory domain and every network, we had the same vulnerable software, often capital assets installed without a care for ongoing maintenance. Working around some of the brightest academic researchers in cyber, I brought a practical, operations-focused mindset to the team. Working with early users, I mapped the technology to their specific requirements.
With Vern Paxson, Robin Sommer and Seth Hall I co-founded Broala to support Bro commercially. Broala became Corelight.
Epoch IV · Orchestration · World’s first Kubernetes company · 2014–2020
Compliance at the speed of containers
I had been experimenting with containers and was convinced of their utility. In early July 2014 I founded Critical Stack with the incredible Dustin Webber to orchestrate containers at scale. Our thesis was that security-conscious organizations like banks and governments would run containers if security and compliance came built in. At Critical Stack we worked hard to make that true on Kubernetes, before Kubernetes was the default. In 2015 Critical Stack was awarded $3 million in the Army’s first Cyber Innovation Challenge, where we deployed the very first Kubernetes for the Department of Defense, and in 2016 one of our customers, Capital One, acquired the company.
At Capital One I led a diverse portfolio of innovation projects, building teams at the intersection of security and compliance. I founded Capital One Software and worked to commercialize some of the amazing technology being built at the bank. I helped drive the donation of Cloud Custodian to the CNCF, built a variety of internal products, and was responsible for the OSPO and a number of other external-facing activities.
While I had been selling into and securing enterprises for almost 20 years at this point, this was my first time being the enterprise. I was immersed in a culture that cares deeply about its customers, its regulatory environment and compliance. It was here that I finally started to understand the enterprise, and gained priceless insight into the why and how of enterprise decision-making. It gave me a new view into the needs and requirements of the enterprise buyer, and it was here that I started to see the inefficiencies at scale across the entire landscape of container-based computing.
Epoch V · Sandboxes · 2019–now
Architecture is destiny; software needs capabilities
Understanding the security, operational and enterprise need for safer ways to build, run and scale software, I started searching for the next promising movement to join. The one I chose was a new standard called WebAssembly. From a technical perspective it met all of the key requirements: an open standard, rigorous design, pluggability and an early, committed group of stewards. I got Capital One involved in the standards work, providing early legal support to the emerging community. With colleagues at Capital One I co-created the early open source projects that would eventually evolve into wasmCloud, which joined the CNCF in 2021 and is now an Incubating project. CNCF wasmCloud is the only multi-tenant Wasm sandbox on the market today. I founded Cloud Native Wasm Day and WasmCon to give the community a home, and served as a CNCF Ambassador in 2024.
Today I run Cosmonic, where we sandbox agent harnesses, code and applications in WebAssembly sandboxes built for untrusted and AI-generated code.
The lesson is still being written. That is what this site is for.
