01 Technical leadership

I lead technical programs and build the systems that make them work.

Technical program leader and hands-on builder across engineering, operations, product, and people.

View selected work
Led
A roughly $200M submarine modernization availability, delivered about two months early.
Built
Six privacy guards deliberately broken; five went red, one did not — and that gap is now closed by a test.
Operated
A build pipeline whose automated writers cannot write outside the paths their task declares.
02

Selected work

A system built to refuse what it should refuse

  1. 01

    Sources arrive with their defects intact

    A note with no date on its next step. A row whose status nobody set. What arrives is kept as it arrived — the record that was read is preserved, not replaced by whatever was parsed out of it.

  2. 02

    Where it came from travels with it

    Each record carries its origin, its identifier there, and when it arrived. Captured records are append-only — corrections arrive as additions, and not even their owner can rewrite what was captured.

  3. 03

    Ownership is part of the key

    A record cannot be created under a parent belonging to someone else — and that holds with the policy layer switched off, so the key is doing the work on its own. Not a rule applied afterwards. A shape the wrong row cannot take.

  4. 04

    Six guards, deliberately broken

    Six privacy guards were deliberately broken to see which tests would notice. Five went red. The sixth did not — and it was the one no test covered. The gap is closed by a test written to fail if that guard is removed.

    The green indicator is the finding. A guard that is working and unverified is indistinguishable from one that is broken, until the day it matters.

  5. 05

    Verified against the real thing, and left unchanged

    Seventeen numbered checks run against the hosted database inside a transaction that always rolls back. And a change to the verification is itself a change that has not been verified — so editing the check file re-triggers the pipeline.

    Read the case study

A five-part sequence about a private system: records are kept as they arrived, carry where they came from, and are bound to their owner by the key itself — so an attempt to attach one person's record to another person's parent is refused even with the policy layer switched off. Six of the system's privacy guards were then deliberately broken; five made tests fail and one did not, which is how an unverified guard was found and covered. The whole thing is checked against the hosted database inside a transaction that always rolls back. The figures in the illustration are invented; the properties they illustrate are not.

A submarine modernization program

Read the case study

A modernization availability of roughly $200 million, delivered about two months early, with a technical team of about thirty.

Availability value (approximate)
$200M
Delivered ahead of plan (approximate)
2 months
Technical team led (approximate)
30

Program leadership · Schedule execution · Cross-functional coordination · Technical risk

A one-person operation, run as a system

Read the case study

Curriculum production rebuilt as a compiler, with the write permissions of its own automation treated as a safety problem.

Artifact types compiled from one source
5
Zones bounding what automation may write
7
Enforcement points: write time and merge
2

Systems design · Build pipelines · Quality engineering · Multi-agent operations

03

How I think

Measure the observed contract.

Read the artifact, not the document describing it. A design document states intent; the running system states fact, and the distance between them is where every confident wrong claim comes from.

Seen in: Waypoint

Enforce in structure, not in prose.

A rule written in a document is a hope; a rule written into a key is a guarantee. Ownership is part of the key, so a record cannot be created under a parent belonging to someone else — and that holds with the policy layer switched off.

Seen in: Waypoint

One system owns a fact.

The same number in two places is two numbers waiting to disagree. Every figure on this site renders from a single constant with its verification date beside it.

Seen in: the operation

A verification that changes has not been verified.

Editing the file that checks the system re-runs the pipeline, because a change to the check is a change. The checks run inside a transaction that always rolls back, so verifying costs nothing and leaves nothing behind.

Seen in: Waypoint

Coverage is declared, not inferred.

A guard that is working and unverified is indistinguishable from one that is broken, until the day it matters. An exempt item is a decision with a name on it; an invisible one is a hole nobody knows about.

Seen in: the operation

04

Background

Nuclear propulsion engineering, submarine programs, enterprise technology, education operations, and product — one career, and the same job in each of them: take something complicated and underspecified, impose a structure on it that holds, and lead the people who execute it.

  • U.S. Naval Academy — B.S., Mechanical Engineering
  • Naval Postgraduate School — M.S., Mechanical Engineering
  • Active-duty submarine officer, qualified in nuclear engineering
  • PMP — Project Management Professional

More about how I work

05

Contact

If this is relevant to a role or a problem you're working on, I'd like to hear about it.

Get in touch