Legacy infrastructure, sovereign AI, and the compliance headaches nobody wants, unified into systems that actually hold up.
About
20+ years hardening and running Linux, z/Linux, and IBM mainframe infrastructure, most recently owning end-to-end security and modernization strategy for a production z/Linux fleet of 1,000+ RHEL/SUSE servers on IBM S/390X mainframes.
Built the Rosetta Stone legacy-modernization pipeline — first shown at Red Hat Summit, expanded at the 2026 Red Hat Conference in Atlanta — and Web3270, an open-source, browser-based TN3270 client with a built-in mainframe security-testing toolkit. Author of eight books on private, auditable AI infrastructure.
Core Competencies
Mainframe modernization, deep Linux architecture, and refactoring the "untouchable" systems everyone else is afraid to open.
Air-gapped LLM pipelines, edge orchestration, and solving problems most teams haven't hit yet.
Bridging strict regulatory standards with AI-driven systems, without breaking either one.
Services
Modernization strategy, legacy code documentation, and code translation for IBM mainframe and z/Linux environments, converting legacy business logic into modern languages for seamless integration into AI and automation pipelines, scoped around live production systems without a rip-and-replace pitch.
Keynotes, conference talks, and workshops on mainframe security, legacy modernization, and sovereign AI infrastructure.
View the speaker sheet →Modernization strategy for IBM mainframe and z/Linux environments, turning undocumented shell scripts and legacy code into fully tested, auditable references while uncovering protocol-level gaps and architectural debt left behind by decades of tribal knowledge. Scoped strictly around live production systems to build clean bridges into modern AI and automation pipelines without a rip-and-replace pitch.
Offensive Security
Hands-on penetration testing across the systems most teams have no one to test: web applications, industrial control, and the mainframe. GPEN / GCFA held.
OWASP-style application assessment: SQL injection, authentication and session flaws, TLS and certificate handling, and the logic bugs scanners miss.
Modbus/TCP, EtherNet/IP (CIP), and Siemens S7comm. Process-aware attacks against simulated controllers, plus zone-and-conduit segmentation and controller hardening to shut them down.
RACF probing, CICS assessment, protocol fuzzing, and MITM traffic modification over TN3270(E), using the Web3270 and EZrecon-2 toolkits.
Training labs I built and released
Deliberately vulnerable widget-shop web lab, 19 planted bugs across SQL injection, TLS and certificate handling, general web, and FTP, each with a documented exploit path and fix, an instructor answer key, and the Widgetorium 101 syllabus. Manual technique first, scanners second. One docker-compose, loopback only.
Mock water treatment plant and power substation with simulated PLCs on real protocols. An attack topology wired with the weaknesses compromising utilities now, a defended topology that closes every one, and a seven-session syllabus modeled on real incidents. Authorised ICS/OT training only.
Products
Stock price alert service — set a high and low on any ticker, get a text or call the instant it crosses. No dashboard to babysit, no app to leave open. Full-stack build: real-time market data with automatic failover, Twilio SMS/phone delivery, PayPal subscription billing, admin tooling, containerized deployment.
Hosted, multi-tenant version of Web3270, browser-based TN3270(E)/TN5250 mainframe terminal access with no client install. Adds accounts and PayPal subscription billing (base/training/full tiers) on top of the same client/bridge engine as the open-source project.
Open source
Browser-based TN3270(E) mainframe terminal client with a built-in security-testing toolkit — RACF probing, protocol fuzzing, MITM traffic modification.
AI + Ansible legacy-code modernization pipeline that documents and tests legacy scripts before converting them.
TN3270E/VTAM client libraries and protocol notes.
LLM observability and hardware-recommendation platform for local, private model deployment.
Publications
Eight books on private, auditable AI infrastructure, from Terraform patterns for LLMOps to mainframe security, sold direct rather than locked behind Apple's cut.