Senior Cloud Engineer &
AI Security Architect

Bridging 25+ years of core engineering foundations with production-grade Generative AI, Model Context Protocol (MCP) integrations, and enterprise Cloud-Native architectures.

View Career History GitHub

Areas of Expertise

Production AI & Security

Securing stateful agentic workflows (Model Context Protocol). Developing advanced RAG architectures, prompt injection defenses, and mitigating OWASP Top 10 for LLMs.

Cloud Platform Engineering

Hands-on engineering across GCP and AWS environments. Managing containerized runtimes (GKE), secure VPC structures, and zero-trust API boundaries (Apigee X/Hybrid).

DevSecOps Automation

Enforcing Policy-as-Code pipelines via HashiCorp Terraform and Rego (OPA). Automating compliance checks directly into GitHub Actions, Harness, and Jenkins pipelines.

Career History

A 25+ year trajectory from deep-dive software development to leading cloud security posture, system virtualization, and high-impact AI/ML platform integrations.

Senior GCP Apigee Engineer
Lloyds Banking Group (Leeds / TCS)
Apr 2026 - Present

Leading the API security architecture, threat modeling, and platform engineering for the enterprise integration of Google’s native Apigee Model Context Protocol (MCP) server.

  • Stateful AI Boundaries: Designing proxy archetypes to secure the transition from stateless REST endpoints to stateful, context-retaining LLM/agentic patterns, mitigating prompt injection and leakage risks.
  • Agentic Knowledge Base: Conceived and built an automated RAG-based agentic pipeline in Python (LangChain/LangGraph) to ingest unstructured telemetry data, using abstract adapters to update Confluence/Backstage dynamically.
  • JIT Access Breakthrough: Proved interactive browser-based JIT console sessions break stateless pipelines (Terraform), winning team-wide consensus to deploy headless programmatic JIT endpoints.
Senior Vice President - API & AppSec Engineering Lead
Citi (London / Hybrid)
Jan 2023 - Apr 2026

Led the global engineering strategy for Application and API Security enablement across the bank's multi-cloud footprint.

  • Decoupled DAST Broker: Ideated and coded a custom DAST-as-a-Service broker platform in Python and Java, abstracting internal microservices and CI/CD pipelines from scanning vendors using an asynchronous model.
  • Policy as Code: Integrated custom apigeelint rules and Rego/Open Policy Agent (OPA) validation policies into build pipelines to enforce automated API security compliance gating.
  • AI Triage: Built a prototype RAG and Agentic AI framework running on Google Vertex AI to automate vulnerability log ingestion and prioritization, reducing triage backlogs by 35%.
Software Engineering Team Lead (Smart-Hub Platform)
William Hill (Leeds)
Nov 2021 - Dec 2022

Led platform engineering for the 'Smart-Hub' system consolidation, operating heavily in AWS Cloud Native ecosystems.

  • Legacy Modernization: Applied Domain-Driven Design (DDD) to decompose legacy betting engines into high-throughput Java Spring Boot microservices integrated with Kafka and AWS.
  • Virtualization Bridge: Built a secure containerized bridge using layered Docker images and nested virtualization to interface 16-bit legacy retail till systems with modern cloud backends.
Service Lead / Tech Lead
Yorkshire Building Society (Leeds)
Jul 2020 - Nov 2021

Served as technical lead and architect bridging legacy transaction systems with modern GCP Apigee API gateways.

  • HSM Virtualization Stub: Coded a Java-based, containerized Hardware Security Module (HSM) software stub (JCA/JCE) to simulate transaction signing pipelines, completely unblocking squad testing cycles.
  • Perimeter Hardening: Configured Google Apigee entry points enforcing strict mutual TLS (mTLS) and OAuth 2.0 access patterns to protect core banking channels.
Blaze Solutions Lead (Decision Systems Architect)
Lowell Financial (Leeds)
Dec 2018 - Jul 2020

Acted as principal architect and SME for the Java-based FICO Blaze Advisor rules engine platform.

  • Engineered highly decoupled asynchronous RabbitMQ pathways to bridge core Java decision models with C#/.NET enterprise consumers.
  • Built a custom Java Swing UI wrapper around the Blaze Rules Maintenance Application (RMA), enabling non-technical analysts to safely edit business rules.
Lead Software Engineer SOA (Agile Lead)
Capital One (Nottingham)
Nov 2014 - Nov 2018

Agile engineering lead delivering high-throughput customer-critical core systems.

  • Designed and optimized core banking transaction interfaces using Oracle SOA Suite, Java EE, and complex PL/SQL.
  • Automated manual deployment streams into Jenkins pipelines, initiating the team's early shift towards modern DevSecOps.

Projects & Innovation

Automated Dynamic Knowledge Base

Developed an automated, decoupled RAG-based agentic pipeline utilizing LangChain, LangGraph, and LLMs. It ingests and filters unstructured team telemetry (Teams chats, Confluence, ServiceNow), using a polymorphic adapter layer to dynamically update documentation systems without lock-in.

Tech: Python, LangChain, RAG, Polymorphic OOP, APIs

Lloyds Innovation Week

Automated Cognitive DAST (Agentic AI)

Architected an open-source AI agent that utilizes Google Vertex AI (Gemini APIs) to autonomously translate natural language security instructions and orchestrate OWASP ZAP penetration testing configurations.

Tech: Python, GCP Cloud Run, GenAI, Docker, OWASP ZAP

View on GitHub

Fivetran Connector SDK Contribution

Authored and merged a custom data ingestion connector into the open-source Fivetran SDK to support direct pipelines streaming vulnerability metrics to central BigQuery warehouses.

Tech: Python, Data Engineering, SDK Integration

View Merged PR

Boolean Algebra Solver (WASM)

Ported a historical 16-bit Turbo Pascal codebase from 1991 into modern web browsers. Utilized multi-stage Docker builds and Emscripten WebAssembly (WASM) compilation to execute the algorithm natively in client viewports.

Tech: Pascal, WebAssembly, Docker, Cloud Hosting

View Architecture

Technical Arsenal

Production Agentic AI & Data Science

Python (Advanced) LangChain LangGraph Model Context Protocol (MCP) Context-Aware RAG PyTorch / TensorFlow Scikit-learn

Cloud & Container Platform Infrastructure

Google Cloud Platform (GCP) AWS Cloud Native Kubernetes (GKE/EKS) HashiCorp Terraform Docker Harness Pipelines VPC & Cloud Armor Networking

Gateway Engineering & AppSec

Apigee X / Hybrid OAuth 2.0 & OIDC mTLS / Cryptography Policy-as-Code (OPA/Rego) SAST/DAST Tool Automation Prompt Injection Defense

Core Languages & Decision Systems

Java (Core, Spring Boot) TypeScript / Node.js FICO Blaze Advisor Oracle SOA / OSB SQL & Advanced PL/SQL

Insights & Diary

Technical writing on securing next-generation AI pipelines, static analysis in API gateways, and cloud architecture boundaries.

Published on Medium • Dec 2025

Beyond Configuration: Building an Intent-Based DAST Scanner with GenAI

Exploring how to design declarative intent frameworks that abstract OWASP ZAP using structured LLM outputs to bypass complex scanner configuration, boosting developer security adoption...

Read Full Article
Published on Medium • Oct 2025

Beyond Conventional SAST: A New Approach to Securing Apigee

In high-throughput API gateways, security verification must happen before deployment. Discussing automated static application security testing (SAST) customized for native XML-based Apigee configuration bundles...

Read Full Article