I break & harden the models we're all building on.

Ten-plus years across application security, AI/ML, and teaching — now bringing that AppSec rigor to LLM systems.

About

Security-first, AI-curious

I secure AI-enabled products through application security, threat modeling, secure SDLC, and practical testing that scales across teams.

Security focus

Application security, threat modeling, and secure SDLC — defenses that hold up across enterprise environments.

AI innovation

AI-powered products end to end, bridging security expertise with emerging model capabilities.

Selected research

Things I've broken & hardened

Disclosure · 2019—now

Responsible disclosure

Hunting and reporting critical web-application vulnerabilities through Bugcrowd, HackerOne, and Synack.

Web AppSec Burp Suite
Architecture · 2022—now

Threat modeling & secure SDLC

Leading security architecture and automated testing pipelines for enterprise platforms at scale.

SAST · DAST OWASP
Focus · 2025—now

Securing LLM systems

Applying AppSec discipline to AI — prompt-injection, RAG isolation, and red-teaming agents.

Prompt Eng RAG
Writing · ongoing

Notes from the workbench

Essays on LLM security, evaluation, and building trustworthy AI — written as I learn.

Read the blog
Projects

Built at the intersection of security & AI

FleetSports AI

Inactive

AI-powered sports analytics platform delivering real-time insights and predictions for fantasy sports enthusiasts.

OpenAI Next.js Python PostgreSQL

Preschool Magic Prep

Inactive

Educational AI application helping parents prepare children for preschool with personalized learning activities.

React Native OpenAI Supabase TypeScript

GetWired

Open Source

AI-powered chaotic testing CLI that helps break web apps before users do.

TypeScript AI Testing CLI Open Source
More on GitHub

Open-source experiments, security tooling, and works in progress.

github.com/chevyphillip
Tech stack

Tools & frameworks

Languages
TypeScript Python Go SQL
Security
Pentesting SAST · DAST Threat Modeling OWASP Burp Suite Snyk
AI & ML
OpenAI LangChain RAG Vector DBs
Cloud & DevOps
AWS GCP Docker Terraform
Frameworks
React Next.js Svelte Astro FastAPI
Databases
PostgreSQL Redis Supabase Pinecone
Experience

Where I've worked

2022 — Present

Senior Application Security Engineer

Shutterstock
  • Lead security architecture for enterprise platforms
  • Build automated security-testing pipelines
  • Drive secure development practices across teams
2021 — 2022

Software Engineer

BeeBettor
  • Built a full-stack sports-betting analytics platform
  • Developed real-time data-processing systems
  • Implemented secure payment integrations
2019 — Present

Security Researcher

Bugcrowd · HackerOne · Synack
  • Discovered critical vulnerabilities in major platforms
  • Contributed to responsible-disclosure programs
  • Specialized in web-application security
2020 — 2022

Adjunct Professor

Alfred State College
  • Taught cybersecurity and programming courses
  • Developed hands-on security-lab curriculum
  • Mentored next-generation security professionals
Education

Credentials

M.S. Data Science — ML & AI
University of Phoenix
In progress
B.S. Software Development
Alfred State College
May 2018
A.A.S. Information Technology
Alfred State College
Dec 2015
Let's build something safer

Have a role, an audit, or a hard problem?

Open to full-time roles and select security-research engagements. Email is the fastest way to reach me.