Professional Summary
Principal AI Software Engineer Β· Agentic AI & Zero Trust Architecture Β· Identity Β· Compliance
- IETF Internet-Draft Author β draft-tonyai-a2a-trust-00 (agent-to-agent trust, AI governance; RFC track)
- Hands-on builder, full lifecycle: Agentic workflows (Cursor, Claude Code) deliver an industry-leading 0.04% defect rate (2+ years consistent) β I design, code, and implement every system myself, then own it operationally day-to-day, not handed off after a design doc
- Zero critical production bugs, zero breaches, zero support calls for login/access failures (career)
- Deep expertise: Zero Trust security, identity platforms (Auth0, Okta, Entra ID), AWS, microservices, compliance (SOC2, PCI-DSS, HIPAA)
- Database architecture expert: Schema design, DDL/DML, indexing, and query tuning across Oracle, PostgreSQL, and MSSQL β not tied to one engine
- No vendor services, ever: Every OAuth2/OIDC/SAML identity implementation across my entire career β Auth0, Okta, Entra ID alike β built and delivered myself, without vendor professional services. Literal track record, not a slogan
- Leadership: Tier-0 systems architecture, 50+ engineers mentored, cross-functional influence (Security, Legal, Product, InfoSec) β without stepping away from the keyboard
- Portfolio: Numerous live PhalanxAI solutions, running code, Anthropic certifications at PhalanxAI Security
- Agentic AI specification engineering β full architecture and security model defined before first line of code; zero requirements drift
Security Portfolio Β· Between roles β running code, live demos
Numerous live PhalanxAI solutions, running demos, IETF Draft, Anthropic certifications β Co-piloted by Claude Code
Live solution: JWT chains, HMAC integrity, ReBAC, cryptographic audit trail
Experience
PhalanxAI Security LLC β Remote
Self-Employed Β· Founder & Principal AI Security Engineer | April 2026 β Present
- Zero Trust AI security platform: Designed and built last-mile Zero Trust architecture in Python (FastAPI, Pydantic) β ephemeral identity, MCP security enforcement, on-behalf-of (OBO) delegation, a token broker, policy enforcement, ReBAC, full cryptographic audit trail; integrates with AWS, GCP, Okta, and Entra ID as IdPs. Running code, not slides.
- IETF Internet-Draft first author: draft-tonyai-a2a-trust-00 β agent-to-agent trust and AI governance; X.509 certificate chains, time-boxed revocation, 100% pass rate across 50 conformance tests + 34 red-team attack vectors, reference implementation in Python. Every clause backed by running code.
- Identity & token infrastructure: Built an OktaβAuth0 identity federation broker (Java/Spring Boot resource server, TypeScript thin-client + CDK infra) with a fail-closed DynamoDB kill-switch checked on every request, and a custom RFC 8693 token exchange engine (AWS Lambda + Cognito, DynamoDB-backed revocation) β designed the token lifecycle strategy (minting, rotation, expiry, sub-second revocation) across both.
- Infrastructure security: Built cross-cluster Zero Trust mesh isolation in Python with mTLS rejection (52+ automated tests) and an AWS-native FIPS 140-3 compliance boundary β S3 Object Lock plus KMS-signed audit logs.
- Agentic AI specification engineering: Full architecture and security model defined before first line of code across numerous PhalanxAI solutions; zero requirements drift.
- Cross-platform C++ build & CI: Built a C++17 security scanner (CMake, vcpkg) shipping as native macOS, Linux, and Windows executables β GitHub Actions matrix build runs on real native hardware per platform (no QEMU emulation), vcpkg binary-cached for fast rebuilds, automated CTest suite, artifact publishing per platform. Real dependency stack: AWS SDK C++, Google Cloud C++, OpenSSL, jwt-cpp, yaml-cpp, cpr, nlohmann_json.
- AWS depth, verified across the portfolio: Hands-on, production or PoC-level implementation across 30+ AWS services β EKS, ECS, Fargate, S3, SES, SQS, SNS, Lambda, API Gateway, KMS, IAM, Amazon Verified Permissions, Cedar, Cognito, CloudFormation, EventBridge, CloudTrail, CloudWatch, GuardDuty, CodeBuild, CodePipeline, DynamoDB, RDS, Aurora, ElastiCache, Redis, Secrets Manager, Parameter Store, Step Functions, PrivateLink, CloudFront, Kinesis, Glue, X-Ray, Bedrock, SageMaker β plus Azure (Entra ID), GCP, Terraform. Not surface-level familiarity.
Henry Schein One β Herriman, UT
Principal Software Engineer / Team Lead | July 2023 β April 2026
- Agentic AI adoption, hands-on: Built and personally used Cursor workflows adopted team-wide; set company record with 17 story points in a single sprint. Evaluated Cursor, GitHub Copilot, GitLab Duo, and Claude hands-on before recommending Cursor for company-wide rollout β ranked top 50 company-wide for adoption. Sustained 0.04% defect rate across 10+ years, recognized by SVP of Engineering and CTO as highest-performing on velocity, output, and defect rate.
- Safe AI at scale: Designed and personally built the AI Safety & Deployment Framework used across HSO β shift-left review, isolated contexts, atomic changes, human gates. Delivered zero production defects; replicable pattern for any org scaling AI safely.
- 85k+ Auth0 users at scale: Sole architect + implementer + rollout owner β hand-coded the custom login UI, adaptive MFA, SMS integration, and a WebAuthn/FIDO2 pilot myself, no vendor pro services. Platform sustained 3Γ daily concurrent logins with zero rate-limit errors.
- Repeatable hardening pattern library (build-once, reuse-many): Wrote the M2M (OAuth2 client credentials) and Entra ID OBO patterns once, reused them for every subsequent 3rd-party integration (Worldpay, partner APIs); session hardening (Session Kill Switch) reused platform-wide, custom Auth0 login UI reused as the FE/UI hardening baseline elsewhere.
- SAML/Entra ID migration, 200+ users, SOC2-driven: Wrote the SAML 2.0 golden path myself (adopted by 3 other HSO products), then led the migration off manual DB-based logins onto full SSO with Entra ID SP flow, RBAC, and JIT provisioning β personally defined the role/entitlement mapping. Cutover was compliance-driven (SOC2), not optional; IT adopted my role framework organization-wide.
- IAM operations, standing escalation point: Owned the internal support tool our techs used daily β fixed bugs, shipped features, was paged directly when SSO broke in production. Built the access/eligibility reporting (bot/ban, Auth0 eligibility, migration tracking) presented to leadership every sprint demo; that data-driven track record is what earned me ownership of the broader auth/security modernization effort.
- Enterprise DSO federation: Designed and built the Auth0 IdP federation for the largest DSO customers myself β mapped each DSO organization to the PMS so customers bring and use their own IdP/users. Proposal accepted first presentation; SOC2 maintained throughout.
- Real-time threat response: Neutralized 2 simultaneous live attacks (DDoS + data exfiltration) hands-on, kept the platform online. Greenfield inventions: Session Kill Switch, Magic Mint (token binding), Actions Mapping Engine, Email Bounce Engine (AWS SES/SQS/SNS, cut support tickets 90% company-wide), PIN Step-Up Auth.
- Technical leadership, department-wide: The recognized security authority for the department for an extended period β evaluated and personally built what was chosen (Auth0, Okta, Entra ID), not just signed off on it. Team's mandate grew from bug-fixing to owning AppSec outright; personally trained the CISO's cloud engineering team on Auth0 and my pen-test remediation approach. Authored HSO-wide security patterns and mentored 90%+ of the team.
- Legacy impact: Post-departure, HSO stood up a dedicated AppSec team to replace one engineer's security work. All Auth0 code still bug-free, zero login/access failure support calls.
KeSTA I.T. β State of Utah β Salt Lake City, UT
Lead Java Developer | October 2022 β July 2023
- Minutes β seconds: Oracle-to-PostgreSQL migration (zero data loss); cut query response time via targeted indexing + refactoring. Two senior architects: "Never seen that volume and quality from one engineer in that timeframe."
- Stack modernization: Java 8 / AngularJS β Java 17 / Spring Boot / Angular in high-security government environment.
- Automated quality gates: GitHub Actions pipelines + OpenAPI/Swagger specs eliminated cross-team integration friction.
Henry Schein One β Herriman, UT
Principal Software Engineer / Team Lead | June 2021 β October 2022
- eRx & clinical platform integrations: Designed the role-based access model for the DoseSpot (electronic prescribing) integration β separate Clinician (prescriber) and Proxy (staff/dentist) roles alongside doctor-portal and patient logins β where Proxy users queue a prescription via delegated access, gated by the EPCS-compliant controlled-substance workflow (DEA-mandated two-factor signing) before the Clinician can sign and transmit it. Wrote the eRx business logic myself (later adopted platform-wide by the team), helped implement multi-tenancy directly in DoseSpot's own codebase, delivered non-eRx PMS integrations, and helped the clinical team implement Veradigm (EHR/clinical platform).
- 92% faster deployments: Personally led and coded the Grails 3 β Java 17 / Spring Boot monolith-to-microservices decomposition (1.5 hrs β 13 mins). Wrote the OpenFeign service-to-service integration pattern myself; it became the chosen standard for the rest of the Grails/Groovy β Java migration, not a one-off.
- 100% remediation rate: Wrote the fixes to close all critical + medium pen-test findings in 3 sprints; zero findings on SSO/auth flows β Security-by-Design.
- Automated security gates: Built GitLab/Harness pipelines (Snyk, SpotBugs, CheckStyle, JaCoCo, Jest) on every commit myself.
- Infrastructure as code: Wrote the Terraform IaC for the Spring Security gateway myself β provisioned, versioned, auditable from day one.
- Team onboarding: Trained engineering + QA on Kafka patterns, identity standards, Event Storming; reduced event-driven service design time.
Henry Schein One / Henry Schein Practice Solutions β Herriman, UT
Full-Stack Staff Engineer / Founding Integration Architect / Team Lead | August 2012 β June 2021
- Auth stack evolution: Architected and personally wrote the PMS identity layer from scratch; evolved: Basic Auth β OAuth2 β SAML 2.0 β M2M β JWT/Bearer. Every auth paradigm today traces to this work.
- 10k+ enterprise SSO users: Designed and hand-coded the Enterprise SAML 2.0 (IdP + SP) integration with Okta + Entra ID. By 2018, 3 other HSO products adopted it β one investment, cross-product revenue.
- Entra ID OBO platform: Designed and built a greenfield OBO flow from zero, wrote the code end-to-end; adopted by multiple teams, support tooling used daily by support/management staff.
- Solo platform architect (2012β2019): Owned architecture, technical strategy, and wrote the code β plus Scrum and infrastructure β simultaneously until dedicated teams stood up in 2019. Then entrusted full CI/CD pipeline ownership for entire PMS.
- First external pen-test: Lowest finding count in company history. Zero successful breaches. SOC2 maintained.
- Stopped DDoS attacks that had previously taken the platform offline; invented and personally coded the foundational access control (DB schema, seed rights, multi-tenancy violation checker).
- Full-stack tech leadership: AWS ECS β EC2 + Kubernetes, Kafka/DDD, PostgreSQL, Spring Boot, React/Vue/Next.js, GitLab CI/CD β wrote production code across every layer. Rebuilt the frontend by hand from jQuery/Backbone to a modern stack.
- Company-wide database authority: Served on the DB schema + standards team; personally designed schema patterns adopted across products. Go-to engineer company-wide for both security and database architecture, hands-on not just advisory.
- Real-time platform reliability: Engineered real-time update engine, zero-conflict scheduling, multi-tenancy architecture for enterprise integrations.
Technical Core
AI & GenAI (SME): Agentic Workflows (Cursor, Claude Code, GitHub Copilot, GitLab Duo, Gemini), Claude Opus, Claude Sonnet, Extended Thinking, Large Language Models (LLMs), Prompt & Context Engineering, Prompt Evaluation Gates, MCP, FastMCP, RAG, Pinecone, AI Agent Orchestration, AI Agents, MCP Servers, Agent Skills, Claude in Amazon Bedrock, A2A Trust, Agent-to-Agent Identity, AI Cost Engineering, Token Budgeting, Bedrock Knowledge Base, Bedrock Guardrails, OWASP LLM Top 10, MITRE ATLAS, ISO/IEC 42001, OpenAPI/Swagger.
Identity & Security (SME): Zero Trust Architecture, Authentication (AuthN), Authorization (AuthZ), Spring Security, SAML 2.0, OAuth2, OIDC, PKCE, WebAuthn, FIDO2, Auth0, Auth0 Deploy CLI, Auth0 SPA SDK, Auth0 Custom Login UI (Vue, React, JS), IdP Claims & Scopes Mapping, Token Claims Customization, SAMLβOIDC IdP Federation (Okta SAML into Auth0 Enterprise Connection), Okta, Entra ID, JumpCloud, Keycloak, CheckPoint, SSO Deployment & Rollout, IdP Provisioning (internal & enterprise DSO), M2M Identity, Customer-Facing SSO Verification, MFA, RBAC, ReBAC (OpenFGA / Zanzibar, BFS graph traversal), SCIM, JIT Provisioning, User Federation, JWT (RS256), RFC 8693 Token Exchange, RFC 9449 DPoP, RFC 7009 Token Revocation, RFC 9562 (UUIDv7), Token Broker Architecture, HashiCorp Vault, mTLS, X.509 / PKI Certificate Chains, SOC2, PCI-DSS, OWASP Top 10, NIST 800-53, Worldpay, Wireshark, Fiddler, Snyk, pip-audit, Pen-Test Remediation.
Cloud & Platform Engineering: AWS EKS, ECS, Fargate, S3, S3 Object Lock, SES, SQS, SNS, Lambda, API Gateway, Application Load Balancer, KMS, IAM, IAM Policies, Amazon Verified Permissions, Cedar, Cognito, Amplify, Organizations, CloudFormation, AWS CDK, AWS SAM, EventBridge, CloudTrail, CloudWatch, GuardDuty, Config, Audit Manager, AWS CloudShell, AWS CodeCommit, CodeBuild, CodePipeline, Amazon ECR, DynamoDB, RDS, Aurora, ElastiCache, Redis, Secrets Manager, Parameter Store, Step Functions, PrivateLink, CloudFront, Kinesis, Glue, X-Ray, Bedrock, SageMaker; Azure (Entra ID), GCP; Terraform, YAML IaC, Bash.
CI/CD & Platform Engineering: VS Code, Git, GitLab CI/CD, GitHub Actions (cross-platform matrix builds), Harness, TeamCity, AWS CodeCommit, Kubernetes, Helm, Docker, Ansible, CMake, vcpkg, CTest, GitLab Vault, Secrets Management in Pipelines, Ephemeral Environments, YAML IaC.
Backend (Java/C++/C#): Python, FastAPI, Pydantic, TypeScript, Java 17, Spring Boot, Spring MVC, C, C++, C#, .NET, Go (familiar), Groovy/Grails, Node.js, Kafka/Confluent (DDD/Avro), RabbitMQ, WebSockets, HL7 (Health Level 7), X12 (ASC X12 EDI β claims 837 / EOB 835), Microservices, Monolith to Microservices Migration, Distributed Computing, Asynchronous Systems, Event-Driven Architecture, Software Architecture and Design, DDD, REST, Apigee, OpenFeign, Twilio, Maven, Gradle, JUnit, Spock, Mockito, JaCoCo, Software Testing, SOLID, DRY, Agile, Scrum.
Frontend: React, Vue.js, JavaScript, jQuery, Backbone, HTML5, CSS3, SASS.
Data: DDL, DML, DB Performance Tuning, Query Optimization, Schema Design, Oracle 19c, PostgreSQL, MySQL, MSSQL, Azure SQL Edge, NoSQL, Liquibase, Flyway, Hibernate, GORM, JPA, Spring Data.
Observability: Dynatrace, Splunk, AppDynamics, CloudWatch, Spring Boot Actuator, Performance Tuning, SLA/SLO Monitoring.
Engineering Leadership: Team Leader, Scrum Master, Agile Ceremonies, Technical Design Docs, Shift-Left Engineering, Code/DB Reviews, Mentorship, Cross-Functional Communication (Engineering, Legal, Security, PM, InfoSec), Vendor Evaluation, Stakeholder Management.
Earlier Career
Symantec
Principal Software Engineer & Tech Lead
- Restore Anyware (P2V/V2P DR), Protection Center (CISO console)
- Active Directory expertise, Patent filed US8103747
- Symantec Star Award, 2Γ A++ performance
Kaseya
Senior Software Engineer
- Kaseya Directory Services, Kaseya Backup
- Active Directory, LDAP, AWS S3, C++, C#, .NET
Additional experience: Healthcare systems (Misys), fintech (Flying J), biometric security, US Army (SATCOM, Top Secret clearance, Honor Student)
Books That Shaped the Craft
A self-taught engineer is only as good as the books he chose to learn from. These are still on the shelf:
- Design Patterns: Elements of Reusable Object-Oriented Software β Gamma, Helm, Johnson, Vlissides (Gang of Four), 1994
- The C++ Programming Language: Special Edition (3rd Edition) β Bjarne Stroustrup, 1997
- Object-Oriented Programming in C++ β Robert LaFore, 1998
- 19 Deadly Sins of Software Security β Howard, LeBlanc & Viega, McGraw-Hill, 2005
- The Pragmatic Programmer: Your Journey to Mastery (20th Anniversary Ed.) β Thomas & Hunt, 2019
- Refactoring: Improving the Design of Existing Code (2nd Ed.) β Martin Fowler, 2018
- Becoming an Indispensable Employee in a Disposable World β Neal Whitten, Prentice Hall, 1994
Education & Continuous Learning
- Anthropic Academy β AI Agents, RAG, MCP Servers, Agent Skills; Claude in Amazon Bedrock; Claude with Google Cloud's Vertex AI; Introduction to Subagents (certifications at PhalanxAI Security β Achievements)
- Self-directed: CTO strategy, AI engineering, cloud architecture β YouTube, Pluralsight & Udemy
- Atlantic Computrain β Sun Java 2 Programmer Certificate
- Certified Careers Institute β AOS, Computer Science, 3.8 GPA
- US Army Signal School β Computer Operator Certificate (Honor Student)
- US Army Signal School β Satellite Systems Operator Certificate (Honor Student)