The cryptography behind Login.gov
As Security Architect at AWS I partnered with the GSA CISO to design a
NIST-peer-reviewed, two-layer cryptographic scheme for Login.gov. It seals each
person's data under their own password, so it stays private even from privileged
insiders.
Login.gov's own August 2026 program roadmap puts the service at 180+ million user
accounts, 500+ million sign-ins a year, 700+ live sites and services, and 54
agencies and states.
Passed
FedRAMP office review
Cloud security at federal scale
I led the TIC 2.0 Overlay pilot as Security Officer at 18F, proving federal systems
could meet Trusted Internet Connection requirements while running on native cloud
services, assessed against NIST SP 800-53. Run with DHS, Sandia National
Laboratories, the FedRAMP office and AWS.
It passed, and I presented the findings at AWS re:Invent 2015. FedRAMP
authorizations followed for Login.gov, cloud.gov and vote.gov.
2
Solutions productized by AWS
Amazon built my work into the product
I published geographic filtering for AWS WAF as an official AWS sample. It proved
popular enough with Department of Defense and financial services customers that
AWS built the capability into the product itself.
My GuardDuty threat-intelligence automation was adopted into Login.gov's live
security operations. My S3 defense-in-depth guide ranked eighth of 125 posts on the
AWS Security Blog that year, and was cited publicly by Amazon's CTO.
None
Noted
Audit result, 2024 and 2025
The auditors left without a finding
ISO 27001:2022 certified on the first attempt with zero nonconformities, ISOQAR
Stage 2 under UKAS accreditation. The 2024 and 2025 cycles across HIPAA, SOC 2 Type
II, ISO 27001, GDPR, CCPA and LGPD all closed with results recorded as "None Noted".
I did not build these frameworks from nothing. I inherited them, carried ISO 27001
from the 2013 standard to 2022, took PCI DSS to 4.0.1, and added UKAS accreditation
plus the EU, UK and Swiss privacy frameworks, without disrupting a customer or a
certification.
89
Control gaps I put in front of my own CEO
Agentic AI, running under live audit
A fifteen-agent security platform runs in production, chaining triage, enrichment,
response and case-writing across fifteen accounts, with a budget killswitch.
Autonomous endpoint triage closes verified false positives daily under a hard rule
that it may never auto-close anything touching credential access, and the
SOC 2 reasoning is logged for every run.
I activated the ISO/IEC 42001 AI management control set in June 2025, ahead of
demand. Nine months later it answered AI governance gates for two enterprise
accounts. An honest self-assessment surfaced 89 control gaps across 17 domains,
and I took that number to the CEO rather than burying it.
An AI insider incident, contained the same afternoon
An insider moved company data into an unsanctioned AI tool. It was contained in four
hours, with no customer impact and no notification required.
What changed afterwards matters more. It triggered a full AI governance build: every
platform AI capability touching customer data inventoried, an AI Use Policy written
in-house that superseded the version outside counsel drafted, and org-wide guardrails
with a board-approved primary tool.