Security Engineering

Finding the compromise, removing it, and fixing the conditions that allowed it.

My security work grows out of operating long-lived production systems: malware investigation, WordPress compromise cleanup, integrity verification, hardening, and policies that reduce preventable exposure across a large fleet.

I approach incidents as system failures rather than isolated bad files. Recovery includes identifying persistence, restoring trust, preserving business function, and reducing the chance of recurrence.

Philosophy

Engineering Philosophy

Security is not a cleanup step. It is a property of how the system is designed and operated.

Treat every unexplained change as evidence, not noise.

  • Remove persistence mechanisms, not only visible payloads.
  • Verify integrity independently after remediation.
  • Reduce attack surface through updates, retirement, least privilege, and operational standards.

Reduce attack surface through updates, retirement, least privilege, and operational standards.

Problems

Problems I Solve

The most valuable work usually begins where a system has accumulated complexity, operational risk, or assumptions no one has revisited.

  • Persistent WordPress malware and reinfection
  • Unknown web shells and altered core files
  • Legacy plugins and abandoned dependencies
  • Fleet-wide visibility and prioritization
  • Secure recovery without unnecessary destruction of content or functionality

Approach

How I Work

I establish a trustworthy baseline, trace indicators across files, database content, users, scheduled tasks, and configuration, then remove both payload and persistence.

After recovery, I verify from multiple angles and address the operational conditions that made the compromise durable.

Selected Projects

Work that makes the method visible.

WordPress Compromise Recovery

Forensic cleanup and hardening for persistent malware in legacy environments.

  • Payload and persistence analysis
  • Core and plugin integrity checks
  • Recovery followed by operational remediation

AI-Assisted Malware Remediation

Designed AI-assisted workflows that accelerate malware investigation while keeping technical responsibility with the engineer.

AI functions as an analytical assistant. Verification and final judgment remain human responsibilities.

Managed Hosting Policy

A supportability and planned-obsolescence framework for a large production fleet.

  • Defined lifecycle expectations
  • Reduced permanent exceptions
  • Lowered technical debt and response complexity

Multi-Model AI Verification Workflow

Calendar Defender

A practical engineering project exploring collaborative AI review rather than depending on a single model to produce solutions.

Independent AI models reviewed architecture, challenged assumptions, explored edge cases, and critiqued implementation approaches before human synthesis.

The result was not simply better code. It was a repeatable engineering process that improved transparency, reasoning quality, and confidence in technical decisions.

Experience

Representative experience.

Zee Creative · 2011–Present

Lead Web Developer

Lead developer and systems architect for a large, long-lived portfolio of production websites and integrations.

  • 250+ active web environments
  • Custom application and integration development
  • Technical standards, migration planning, launch QA, and incident response

SunGard Higher Education · approximately 8 years

Lead Software Engineer

Technical lead in enterprise higher-education software, working across large Oracle systems, performance testing, defect analysis, and release delivery.

  • Synthetic data generation exceeding one million records
  • Defect cross-reference and recurrence prevention
  • Enterprise release estimation and delivery

Technologies

Core technologies and areas of focus.

Security Work

Incident ResponseMalware AnalysisIntegrity VerificationHardeningAccess Review

Platforms

WordPressLinux HostingPHPMySQLGit

Focus

Persistence DetectionRecoveryAttack Surface ReductionOperational PolicyVerification

Business Value

Why recovery must extend beyond cleanup

Deleting the obvious malicious file may restore a page while leaving the attacker’s access intact.

Durable recovery restores confidence in the whole system and changes the conditions that allowed the incident to persist.

Contact

Let's Talk

For technical leadership, architecture, modernization, or complex systems work, contact me directly.

Contact Julie
A system is not clean because the warning disappeared. It is clean when trust has been rebuilt.