I break & harden the models we're all building on.
Ten-plus years across application security, AI/ML, and teaching — now bringing that AppSec rigor to LLM systems.
Security-first, AI-curious
I secure AI-enabled products through application security, threat modeling, secure SDLC, and practical testing that scales across teams.
Application security, threat modeling, and secure SDLC — defenses that hold up across enterprise environments.
AI-powered products end to end, bridging security expertise with emerging model capabilities.
Things I've broken & hardened
Responsible disclosure
Hunting and reporting critical web-application vulnerabilities through Bugcrowd, HackerOne, and Synack.
Threat modeling & secure SDLC
Leading security architecture and automated testing pipelines for enterprise platforms at scale.
Securing LLM systems
Applying AppSec discipline to AI — prompt-injection, RAG isolation, and red-teaming agents.
Notes from the workbench
Essays on LLM security, evaluation, and building trustworthy AI — written as I learn.
Read the blogBuilt at the intersection of security & AI
FleetSports AI
InactiveAI-powered sports analytics platform delivering real-time insights and predictions for fantasy sports enthusiasts.
Preschool Magic Prep
InactiveEducational AI application helping parents prepare children for preschool with personalized learning activities.
GetWired
Open SourceAI-powered chaotic testing CLI that helps break web apps before users do.
Open-source experiments, security tooling, and works in progress.
github.com/chevyphillipTools & frameworks
Where I've worked
Senior Application Security Engineer
- Lead security architecture for enterprise platforms
- Build automated security-testing pipelines
- Drive secure development practices across teams
Software Engineer
- Built a full-stack sports-betting analytics platform
- Developed real-time data-processing systems
- Implemented secure payment integrations
Security Researcher
- Discovered critical vulnerabilities in major platforms
- Contributed to responsible-disclosure programs
- Specialized in web-application security
Adjunct Professor
- Taught cybersecurity and programming courses
- Developed hands-on security-lab curriculum
- Mentored next-generation security professionals
Credentials
Have a role, an audit, or a hard problem?
Open to full-time roles and select security-research engagements. Email is the fastest way to reach me.