Hello! I’m a software engineer and manager specializing in software security.
Until mid-2026, I worked on Google Chrome’s security team and led teams responsible for network security, cryptography, web platform security, security UX, and counter-abuse (fighting threats like social engineering and scams). During my time on Chrome, I helped deploy post-quantum cryptography in TLS, launched the Chrome Root Program, expanded adoption of HTTPS across the web, and built new detection heuristics and warnings for spoofy domains.
In 2026 I’ll be starting a new role working on agentic security and vulnerability discovery in Google’s central product security team.
I received my bachelor’s degree from Stanford University and master’s degree from MIT (both in computer science). As a student, most of my research centered on deploying client-side cryptography in web applications. I still stay involved in the academic research community by publishing papers about my work on Chrome and serving on program committees.
Other places on the web you can find me:
- Chromium commits
- GitHub (mostly used for web standards work these days)
- Bluesky
- Stack Overflow
You can read popular press about my work here, here, and here.
Outside of work, I live with my spouse and two sons in the San Francisco Bay Area. I enjoy baking, reading, yoga, and hiking in my free time.