The Engineering Club - Security Edition
Get a deep dive into the world of security engineering. Each week, I’ll share insights during my time at Google, explore key topics in cybersecurity and Kubernetes, and draw from my personal experiences.
- Indexed issues, last 90 days
- 4
- Latest publication
- Sep 25, 2026
- Audience
- Checking…
- Earliest in this view
- Jul 6, 2026
Latest issues
Cybersecurity risk and compliance fundamentals (opens the original)
Read excerpt
Before you decide whether a company needs another security tool, you should be able to explain what you’re protecting and what could happen to it.That sounds obvious. But try answering it without saying “our infrastructure,” “our assets,” or “our data.”Which data? Used by whom? What happens if someone copies it, changes it, or makes it unavailable?Those… Read more
How I'd Respond When a Developer Pushes AWS Keys to a Public Repo (opens the original)
Read excerpt
It’s 11:40 on a Wednesday morning. A developer on your team is knee-deep in a feature, moving fast, and commits a config file to get their environment working. git add ., git commit, git push. Done. Back to work.Except that config file had the AWS access keys in it. And the repo is public.Nobody notices for six minutes. Then someone does, and the Slack message lands: “uh, I think I just pushed our AWS keys to GitHub.”Here’s the part most people get wrong about this moment. They treat it like a s
Agentic AI Security: Fundamentals (opens the original)
Read excerpt
There’s a security problem sitting at the heart of every AI agent, and almost nobody building with these tools talks about it honestly.It’s not that the model says something wrong. Every system produces bad output sometimes. The problem is stranger than that.Alarge language model can’t tell the difference between instructions and data. Everything it reads is potentially a command. That includes the web page you asked it to summarize, the GitHub issue you asked it to triage, the email you asked i
How I’d Respond in the First Hour After a Package I Use Got Hacked (opens the original)
Read excerpt
It’s 2:47 on a Tuesday afternoon.You are halfway through a coffee, halfway through a code review, when a message lands in your team Slack. Someone pasted a link. The title reads: “PyPI has quarantined [package name] due to a supply chain compromise.”You recognize the package immediately.<a class="image-link image2 is-viewable-img" href="https://substackcdn.com/image/fetch/$s_!0_hg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0bc
Publishing over time
Last 90 days. Choose a month to open its work.
Recurring subjects
Named in the text we hold. One piece can cover several.
Audience
No verified audience measurement yet.
About this data
Counts cover the work we have indexed. Tone needs enough text and a confident classification. Excerpts and episode notes are not full articles or transcripts.
Identity or attribution wrong? Suggest a correction.