Security

Security work that makes risk easier to see, explain, and act on.

Security platforms, analysis workflows, and internal tools that improve trust without creating unnecessary friction.

Split-view Northstar Security case-management dashboard with a ticket queue and active investigation workspace.
Concept interface for a calmer, more actionable application security workflow.

Application Security Dashboard

I designed and built an internal application security platform that unified ticket management, code review, dependency analysis, and security investigations into a single workspace.

Internal Tool

Security

Northstar Security is an internal application security platform created to consolidate the tools and workflows used throughout the software security review process. Instead of moving between separate applications for ticket management, static analysis, merge request reviews, dependency investigations, and threat analysis, security engineers can complete investigations within a consistent interface designed around evidence-driven decision making. As the sole designer and developer, I was responsible for the product vision, user experience, interface design, and implementation of the platform. The portfolio recreates the application's interface using fictional branding to protect confidential information while accurately representing the workflows, architecture, and design decisions behind the original system.

Signal areas

4

Core views

7

View project
Dark Splunk User-Agent Search interface showing search configuration, progress controls, and an empty results panel.
An internal automation tool that continuously analyzes firewall logs and highlights suspicious User-Agent activity for further investigation.

Firewall User-Agent Analysis Tool

I designed and built an automated firewall log analysis tool that identifies suspicious User-Agent activity and supports more informed WAF tuning and security investigations.

Internal Tool

Security

As part of my application security work, I developed an internal automation tool to analyze firewall logs and surface potentially malicious User-Agent activity that could otherwise be overlooked during manual review. The system parses F5/WAF logs, compares observed User-Agent strings against a maintained database of approximately 1,500 suspicious signatures, and highlights activity worth further investigation. By automating this recurring analysis, the tool helps security teams focus their attention on meaningful signals while providing additional context for firewall rule improvements.

Application SecuritySoftware EngineeringAutomation

Suspicious signatures

~1,500

Analysis cadence

Every 24 hours

Log source

F5 / WAF

View project