Skip to main content

Security Engineering Portfolio Artifact

Publish a public-safe case study without credentials, sensitive topology, personal data, exploitable production details, or uncoordinated vulnerability disclosure.

Include system context; threat model; security requirements; one safely reproduced weakness and verified remediation; automated negative and adversarial testing; host/cloud/platform controls; SBOM, signing, and provenance; detection and incident exercise; architecture decisions; independent-review findings; residual risk; and changes caused by review.

Private evidence is referenced by stable artifact IDs. The oral defense must establish authorship and explain all assisted work declared in the AI-use record.