Blog

Engineering, security leadership, responsible AI, and open source.

22 September 2026 · security-leadership

Product security has to work with the product

Security has to be engineered as part of the system, not bolted on as a checklist — with functional proof, resource-impact proof, and deployment evidence as the definition of done.

17 September 2026 · engineering, security-leadership

From CVE scanning to actual vulnerability management

CVE scanning gives visibility into an embedded image. It doesn't tell you what to do about it — that takes product context, evidence-based triage, and proof that a fix actually reached the device.