NEW

Start with the pressure: sales, launch, abuse, agents, data, or guardrails

Portfolio

David Wolf's Projects

32 projectsView all consultants' work →

Browse capability evidence

Filter by capability, evidence status, and delivery context.

Public-safe examples are grouped by the capability they evidence for AI Security Engineering: governance evidence, product security, detection, research synthesis, enterprise delivery, and adjacent origins.

Engagement type

All projects

Projects

32

Companies

21

Featured

3

Company imagery

32

Public-safe

1

Visible now

32

Showing 32 of 32 public-safe examples. Filters preserve the curated evidence order, so the strongest AI security capability signals stay visible first.

Featured evidence

Pinned project anchors

The most public-facing evidence remains pinned even when the rest of the directory is filtered.

Agentic Browser Security Assessment hero image
Confidential AI Automation Platform2025–2026
Public-safe with caveat

Agentic Browser Security Assessment

A product-security assessment of browser trust boundaries, privileged pages, native bridges, script-injection persistence, credential surfaces, and native command dispatch.

Conducted a deep product-security assessment of browser trust boundaries across native and agentic browser surfaces, including…

MapAttackDefend
Product SecurityBrowser SecurityDesktop SecurityWebView2

Consultants

Confidential AI Automation Platform
Open project
Splunk Product Security Program Buildout hero image
Splunk2013–2015
Public-safe with caveat

Splunk Product Security Program Buildout

Building a scalable, evidence-driven product security function for a global enterprise software platform.

Partnered with Splunk to build and scale the product security program, strengthen secure development practices, and create the…

MapEvidence
Product SecuritySecure SDLCProgram BuildoutEnterprise SaaS
Cornerstone FedRAMP Moderate ATO Security Controls hero image
Cornerstone OnDemand2015–2016
Public-safe with caveat

Cornerstone FedRAMP Moderate ATO Security Controls

A control-architecture and evidence-readiness effort translating FedRAMP Moderate requirements into policy, standards, technical controls, operational procedures, and audit-ready proof.

Supported Cornerstone's FedRAMP Moderate authorization effort by helping turn formal control requirements into security policie…

EvidenceMap
Cornerstone OnDemandFedRAMPFedRAMP ModerateATO

Consultants

Cornerstone OnDemand
Open project

AI Security & Governance Evidence

Public-safe evidence of AI security assessments, operating models, governance evidence, and buyer-facing claim support.

11 projects
The State of AI Security Engineering Report 2026 portrait cover
AI Security LLC2026
Public-safe with caveat

The State of AI Security Engineering Report 2026

A flagship research report turning AI security job-market noise into evidence about roles, skills, control gaps, hiring signals, and the emerging AI security engineering discipline.

Designed and authored a flagship 2026 research report on AI security engineering, using a corpus of AI and security job descrip…

EvidenceMap
AI Security EngineeringAI Security ReportLabor Market ResearchCybersecurity Hiring

Consultants

AI Security LLC
Open project
The AI Security Engineer's Handbook portrait cover
AI Security LLC2026
Buyer-ready evidence

The AI Security Engineer's Handbook

A practical field handbook for turning AI security from policy language into executable engineering work, control evidence, and operator-ready workflows.

Created a practitioner-oriented AI Security Engineering Handbook that translates AI risk, governance, product-security, and age…

MapDefendEvidenceAttack
AI Security EngineeringAI Product SecurityProduct SecurityApplication Security

Consultants

AI Security LLC
Open project
AI Product Security Control Plane hero image
Consulting
Confidential AI-Native Product Team2025–2026
Public-safe with caveat

AI Product Security Control Plane

A compact methodology for connecting AI inventory, threat modeling, prompt injection, agent permissions, RAG authorization, AI supply chain, evidence, and governance.

Framed AI product security as a product-control problem and translated AI risk categories into evidence, backlog, and governanc…

MapEvidence
AI Product SecurityControl PlaneThreat ModelingPrompt Injection

Consultants

Confidential AI-Native Product Team
Open project
Disney IAM SIEM Alert Debugging & Executive Dashboard hero image
Consulting
DisneyCareer Role
Public-safe with caveat

Disney IAM SIEM Alert Debugging & Executive Dashboard

A Splunk-based IAM monitoring and executive reporting project across Disney access-control and identity systems for campuses and offices.

Delivered Splunk-focused IAM and SIEM work for Disney, debugging identity and access-control alerts, building a custom Splunk a…

MapEvidence
DisneySplunkSIEMIAM

Consultants

UNUM LLM Attack Story & Detection Engineering hero image
Consulting
UNUM2024–2025
Public-safe with caveat

UNUM LLM Attack Story & Detection Engineering

A paid consulting engagement using LLM-assisted attack trees, MITRE ATT&CK mapping, ServiceNow asset inventory, enterprise architecture context, synthetic logs, and Splunk SPL detections.

Delivered a two-month consulting engagement for UNUM that used LLM-assisted attack-tree and attack-story generation, MITRE ATT&…

MapEvidence
UNUMAI SecurityDetection EngineeringLLM Attack Stories

Consultants

Hotel Marketers Hospitality Booking Intelligence & GIS Inventory Normalization hero image
Consulting
Hospitality marketing and booking infrastructure2005
Internal/private

Hotel Marketers Hospitality Booking Intelligence & GIS Inventory Normalization

Technical hospitality marketing, destination data, inventory normalization, and direct-booking support for independent hotels.

Reconstructed from 2005-era Hotel Marketers site copy, this case study captures technical hospitality work focused on direct-bo…

Evidence focus: search, retrieval, and data quality
Hotel MarketersHospitalityTravelInformation Science

Consultants

Hospitality marketing and booking infrastructure
Open project
Caya Forex PCI DSS Level 3 Compliance hero image
Consulting
Forex trading platform2010
Internal/private

Caya Forex PCI DSS Level 3 Compliance

PCI DSS Level 3 scoping, gap analysis, and compliance program delivery for a forex trading and payment processing platform.

Delivered a PCI DSS Level 3 compliance engagement for Caya, a forex trading and payment processing platform. Work covered scopi…

Evidence
CayaForexPCI DSSLevel 3

Consultants

Forex trading platform
Open project
Trada — Data.com B2B Sales Contact Intelligence & ABM Rainmaker hero image
Consulting
Performance advertising platform2011
Internal/private

Trada — Data.com B2B Sales Contact Intelligence & ABM Rainmaker

3x Salesforce Data.com Rainmaker recognition for OSINT-driven B2B contact mining, normalization, and ABM outreach campaign delivery for a performance advertising platform.

Delivered B2B contact intelligence, OSINT-driven contact mining, and ABM outreach campaign execution for Trada, a performance a…

EvidenceMap
TradaData.comSalesforceRainmaker

Consultants

Performance advertising platform
Open project
Cogstate Cognitive Measurement Delivery for the Australian Defence Force hero image
Consulting
Cogstate2012
Internal/private

Cogstate Cognitive Measurement Delivery for the Australian Defence Force

Clinical and cognitive-assessment technology delivery for Australian Defence Force-linked workflows, emphasizing data integrity, privacy, workflow reliability, evidence, and customer trust.

Contributed to technology delivery in a Cogstate engagement on behalf of the Australian Defence Force, where cognitive-assessme…

MapEvidence
CogstateAustralian Defence ForceHealth TechnologyClinical Research

Consultants

Cogstate
Open project
Pathwwway iGaming — Deputy Head of Technology & ISO 27001 Audit hero image
Pathwwway iGaming2017
Internal/private

Pathwwway iGaming — Deputy Head of Technology & ISO 27001 Audit

Technology leadership and ISO 27001 ISMS audit for an iGaming platform, spanning delivery ownership, platform operations, security-aware execution, and certification-readiness consulting.

Served as Deputy Head of Technology for a Pathwwway iGaming engagement before Forescout, guiding technology delivery, platform…

EvidenceMap
PathwwwayiGamingDeputy Head of TechnologyTechnology Leadership

Consultants

Pathwwway iGaming
Open project
NIST NICE Cyber Workforce Research Program hero image
Consulting
Sapient Search Group2024–2026
Public-safe with caveat

NIST NICE Cyber Workforce Research Program

A cyber-workforce research program featured at RSA Conference, bSides NYC, and Infosecurity Europe, translated into a talent-intelligence and ATS workflow layer.

Developed a NIST NICE Cyber Workforce research program focused on role language, workforce taxonomy, and cyber-workforce signal…

MapEvidence
NIST NICE Cyber WorkforceSapient Search GroupAI RecruitingATS Platform

Consultants

Sapient Search Group
Open project

Product Security & AppSec Evidence

Architecture reviews, trust-boundary work, secure SDLC, application security, and product risk reduction.

4 projects
AI Governance Controls with Garak, NeMo Guardrails, Presidio & Promptfoo hero image
Confidential AI Governance Program2025–2026
Public-safe with caveat

AI Governance Controls with Garak, NeMo Guardrails, Presidio & Promptfoo

Implementing practical AI control evidence for ISO 42001, NIST AI RMF, AIMS, agent identities, permissions, red teaming, privacy, and output evaluation.

Designed a practical AI governance control layer using Garak, NeMo Guardrails, Microsoft Presidio, Promptfoo, agentic identitie…

MapEvidenceAttackDefend
AI GovernanceAI Product SecurityISO 42001NIST AI RMF

Consultants

Confidential AI Governance Program
Open project
GitOps Multi-Agent SDLC Automation Platform hero image
Internal Product2025–2026
Public-safe with caveat

GitOps Multi-Agent SDLC Automation Platform

A Git-backed agentic software delivery system using workflow graphs, code remediation agents, evaluator agents, acceptance criteria, audit trails, issue linkage, and AI-assisted engineering controls.

Designed and implemented a GitOps-oriented multi-agent SDLC automation platform where AI agents analyze repositories, propose f…

DefendMapEvidence
GitOpsMulti-Agent SDLCAgentic Software EngineeringBug Remediation

Consultants

Internal Product
Open project
Tauri Rust AI Sidecar, Apple Bridge & Capability Mesh hero image
Internal Product2023–2026
Public-safe with caveat

Tauri Rust AI Sidecar, Apple Bridge & Capability Mesh

A native AI sidecar architecture using Tauri, Rust, MITM proxying, WebSocket bridges, 160+ adapters, Apple-native APIs, VPN/network capabilities, and a dynamic capability mesh across devices and clients.

Designed and built a native AI sidecar platform using Tauri and Rust, combining MITM proxying, WebSocket pub/sub bridges, 164 s…

MapEvidence
TauriRustNative AI SidecarMITM

Consultants

Internal Product
Open project

Research & Publications

Research, review, and artifacts that translate technical work into reusable evidence.

11 projects
The AI Security Engineering Field Guide portrait cover
aisecurity.llc2026
Public-safe with caveat

The AI Security Engineering Field Guide

A compact, action-oriented field guide for AI security engineering practitioners working in fast-moving environments.

The AI Security Engineering Field Guide is a compact, action-oriented companion for practitioners who need direct guidance — no…

EvidenceMap
AI SecurityField GuidePractitioner ToolsRapid Reference

Consultants

aisecurity.llc
Open project
Forescout Device Cloud Elastic/Kibana Analytics Platform hero image
Forescout2019–2020
Public-safe with caveat

Forescout Device Cloud Elastic/Kibana Analytics Platform

Large-scale connected-device analytics using Forescout Device Cloud, Elastic, Kibana, and security-research workflows to turn millions of device records into report-ready security evidence.

Built and executed Elastic/Kibana-style analytics workflows over Forescout Device Cloud data to support security research, sect…

EvidenceMap
ForescoutDevice CloudElasticKibana
Forescout
Open project
Forescout Connected Medical Device Security Report hero image
Forescout2019–2021
Public-safe with caveat

Forescout Connected Medical Device Security Report

Device Cloud research on connected medical-device segmentation, insecure protocols, default credentials, legacy systems, and clinical-network exposure.

Contributed to Forescout connected medical-device research using Device Cloud analytics to examine segmentation failures, insec…

EvidenceMap
ForescoutConnected Medical DevicesHealthcare SecurityIoMT
Forescout
Open project
Forescout Enterprise of Things Security Report 2020 hero image
Forescout2020
Public-safe with caveat

Forescout Enterprise of Things Security Report 2020

Device Cloud research identifying the riskiest IoT devices across financial services, government, healthcare, manufacturing, and retail.

Contributed to Forescout's Enterprise of Things Security Report research, using Device Cloud analytics and Elastic/Kibana-style…

EvidenceMap
ForescoutEnterprise of ThingsState of IoT Security 2020Device Cloud
Forescout
Open project
Forescout Banking on Security Financial Services Research hero image
Forescout2020
Public-safe with caveat

Forescout Banking on Security Financial Services Research

Device Cloud research on financial-services device risk, flat networks, IoT/OT proximity, POS exposure, Windows lifecycle risk, and segmentation gaps.

Contributed to Forescout's Banking on Security financial-services research, using Device Cloud analytics and Elastic/Kibana-sty…

EvidenceMap
ForescoutBanking on SecurityFinancial Services SecurityDevice Cloud
Forescout
Open project
Forescout Operational Technology Security Research hero image
Forescout2019–2020
Public-safe with caveat

Forescout Operational Technology Security Research

Device Cloud and research-backed analysis of OT, IoT, industrial, unmanaged, and cyber-physical systems as enterprise attack surfaces.

Contributed to Forescout operational-technology and Enterprise-of-Things research by using Device Cloud analytics and Elastic/K…

EvidenceMap
ForescoutOperational TechnologyOT SecurityIndustrial IoT
Forescout
Open project
Forescout DTEN / WIRED-Featured Offensive Security Research hero image
ForescoutCareer Role
Public-safe with caveat

Forescout DTEN / WIRED-Featured Offensive Security Research

Offensive security research into connected-device risk, enterprise exposure, and real-world exploitability, later featured in WIRED coverage.

Contributed to offensive security research involving DTEN and connected-device risk, helping expose how enterprise collaboratio…

EvidenceAttackMap
ForescoutDTENWIREDOffensive Security Research
Forescout
Open project
Devo Security Research & Conference Program hero image
Devo2022–2023
Public-safe with caveat

Devo Security Research & Conference Program

A public security research program turning SIEM deployment analysis, cloud detection patterns, architecture innovation, and SOC maturity findings into RSA, Infosecurity Europe, and CloudNativeSecurityCon-ready narratives.

Developed and contributed to Devo security research that converted customer deployment analysis, SIEM maturity patterns, detect…

EvidenceMap
DevoSecurity ResearchConference ResearchRSA

Consultants

Devo SIEM Reference Architecture, Taxonomy & Detection Validation hero image
Devo2022–2023
Public-safe with caveat

Devo SIEM Reference Architecture, Taxonomy & Detection Validation

Architecture innovation work redesigning SIEM reference architectures, standardizing detection taxonomy, validating Exchange content, and turning hundreds of enterprise deployments into maturity patterns.

Led and contributed to Devo architecture innovation work focused on SIEM reference architectures, detection taxonomy, Exchange-…

MapEvidenceAttack
DevoSIEMCloud SIEMReference Architecture

Consultants

Mapping Motives: Analysis of 2,000 Enterprise Cloud Detections hero image
Devo2023
Public-safe with caveat

Mapping Motives: Analysis of 2,000 Enterprise Cloud Detections

Linux Foundation / Cloud Native SecurityCon research on enterprise cloud detections, cloud SOC maturity, ATT&CK-aligned motives, and the growing importance of cloud-native telemetry in SIEM programs.

Presented Cloud Native SecurityCon North America 2023 research with Joshua Smith at Devo, analyzing 2,000 enterprise cloud dete…

MapEvidenceAttack
DevoCloudNativeSecurityConLinux FoundationCNCF

Consultants

RiverBanks Workforce Development LMS Suite hero image
RiverBanks / Internal Product2023–2026
Public-safe with caveat

RiverBanks Workforce Development LMS Suite

A three-framework workforce-development product suite combining EMPOWER psychometrics, CORE interview intelligence, RISE self-authoring, SCORM/xAPI/LTI packaging, university pilots, and AI-generated coaching reports.

Designed and built a workforce-development LMS product suite around three major frameworks: EMPOWER for psychometrics and perso…

MapEvidence
RiverBanksWorkforce DevelopmentLMSEMPOWER

Consultants

RiverBanks / Internal Product
Open project

Enterprise Systems & Data Quality

Conservative public-safe summaries of prior enterprise delivery, data quality, search, retrieval, and system mapping work.

3 projects
Forescout Rapid Response Program hero image
Forescout2017–2018
Public-safe with caveat

Forescout Rapid Response Program

A security response operating model for urgent product, customer, vulnerability, and research-driven risk events in enterprise device-security environments.

Contributed to Forescout rapid response work by helping coordinate security research, product risk triage, technical validation…

MapEvidence
ForescoutRapid ResponseProduct SecuritySecurity Research
Forescout
Open project
Syntryx OSINT Platform Product Buildout hero image
Syntryx2006–2010
Public-safe with caveat

Syntryx OSINT Platform Product Buildout

Leading product and engineering for a 2B-page open-source intelligence platform using high-throughput crawling, PostgreSQL-scale ingest, ML, NLP, clustering, search analytics, and graph visualization.

Led product and engineering for Syntryx, an open-source intelligence platform for multi-channel web and behavioral data, managi…

EvidenceMap
SyntryxOSINTOpen-Source IntelligenceProduct Leadership

Consultants

Cendant / Orbitz Affiliate Growth, ML Itinerary Generation & GDS Cleanup hero image
Cendant / Orbitz2005–2006
Internal/private

Cendant / Orbitz Affiliate Growth, ML Itinerary Generation & GDS Cleanup

Technical marketing, ML-style multileg itinerary generation, and geographic waypoint and GDS inventory cleanup to support affiliate growth, search demand capture, and travel-content expansion.

Supported affiliate-program growth and technical marketing by developing ML-style methods for generating high-value niche multi…

EvidenceMap
CendantOrbitzGTA Gullivers Travel AssociatesAffiliate Marketing

Consultants

Cendant / Orbitz
Open project

Public-safe caveat

Projects use conservative public-safe language. They avoid raw job-description text, ATS payloads, personal data, secrets, private customer records, unapproved quotes, sponsor negotiation notes, unsupported maturity claims, accusatory company-level framing, and psychometric diagnosis.