Applied Security Engineering
Practices what he preaches on his own platforms: isolated read-only public services, least-privilege database roles, hardened containers (non-root, read-only rootfs), TLS/CSP discipline, firewall and fail2ban operations, and recurring security audits of his own internet-facing surfaces.