I grew up without a fixed classroom or a fixed country. Worldschooling meant learning math from a museum in one city and learning what fragility actually looks like in another, such as escaping the war in Ukraine in 2022, helping coordinate stranded Filipino nationals to safety, and watching a currency lose value by the hour. Those aren't ever simply abstractions to me; they're the reason I care deeply about financial, digital, and governmental systems, as they can fail people with almost no warning and at the power of a few.
That instinct followed me home. When members of my own family were targeted by scam networks, I built Project Aghoy, a free tool to help Filipinos recognize and report scams before they lose everything. It's the same instinct behind everything I do now: cybersecurity, AI governance, and internal tooling aren't careers to me so much as the modern version of showing up for people when the systems around them can't be trusted.
INITIALIZING UPLINK
Establishing orbital map…
◉
GLOBE OFFLINE
WebGL context unavailable - node telemetry is still listed below.
Core Pillars
01 / 03 · PILLAR
Cybersecurity
Protecting livelihoods against more than just social engineering. Cybersecurity as the baseline for human throughput in an adversarial landscape.
Interactive security dashboard and gamified post-mortem analysis utility to recognize and report scams.
DRAWN:R.C.F.SSCALE:TRUEREV:2.1.7SHEET:03 OF 05
4.1 Credentials
Verification of specialized expertise and industry certifications.
[PANEL04/08]
Certifications
Fellow of Management Systems Auditing (FMSA)MASTERMIND // AI & PRIVACY
[VERIFIED]
ISO/IEC 27001:2022 Lead AuditorMASTERMIND // ISMS
[VERIFIED]
ISO/IEC 42001:2023 Lead AuditorMASTERMIND // AI GOVERNANCE
[VERIFIED]
ISO/IEC 27701:2025 Lead AuditorMASTERMIND // PRIVACY INFORMATION
[VERIFIED]
OCI Foundations & AI Foundations AssociateORACLE // CLOUD SYSTEMS
[VERIFIED]
ISC2 Certified in Cybersecurity (CC)ISC2 // CORE CYBER
[VERIFIED]
IBM & ISC2 Cybersecurity SpecialistIBM & ISC2 // SECURITY OPS
[VERIFIED]
CS50's Introduction to CybersecurityHARVARDX // ACADEMIC
[VERIFIED]
International GED High School Equivalency DiplomaGED TESTING SERVICE // HIGH ACHIEVER
[VERIFIED]
DRAWN:R.C.F.SSCALE:TRUEREV:2.1.7SHEET:04 OF 05
> 00.5 // TOOLCHAIN
5.1 What I've Worked With
Full inventory: every entry has shipped in a project, engagement, or audit on this site.
No proficiency theater; ask me about any of them.
[PANEL05/08]
Python
C++
JavaScript
SQL
Bash
HTML / CSS
Cloudflare Workers
Cloudflare D1
Cloudflare R2
REST API design
Rule-based NLP
ISO/IEC 27001
ISO/IEC 42001
ISO/IEC 27701
Wireshark
Scapy
tcpdump
OSINT
OpSec / VPN hardening
Incident response
Cloudflare Pages
Wrangler
Docker
OCI
VM lab environments
Three.js
D3.js
Canvas API
Tailwind CSS
GSAP
Browser extensions
LangChain / LangGraph
LLM API integration
Agent orchestration
Model routing / eval
Open-weight models
Git
SQLite
Linux Commands
CSP / security headers
WebGL2
Howler.js
ipwhois.app API
Google Fonts API
TOOLCHAIN_COUNT: 44 ENTRIES // FILTER: ALL
SELECT A TOOL TO INSPECT
DRAWN:R.C.F.SSCALE:TRUEREV:2.1.7SHEET:05 OF 05
> 00.6 // CAPABILITIES
6.1 What The Toolkit Can Hold
Every capability is drawn as a filed spec (title-blocked and measured). These are the surfaces I operate, surveyed end to end.
[PANEL06/08]
Spec Grid
SPEC · 01
Detection
Purple-team harnesses that replay TTP chains against the live SOC and surface blind spots before red does.
SPEC · 02
Governance
Policy-as-drawing: control boundaries, data-flow trust zones, and verification gates rendered as schematics.
SPEC · 03
AI Systems
Evaluation scaffolds for model behaviour: deterministic when it matters, sampled when it scales.
SPEC · 04
Architecture
Dependency graphs with verified data-flow boundaries and explicit trust zones, drawn not described.
SPEC · 05
Supply Chain
Propagation maps: dependency → hook → exfil path, rendered as a kill-chain DAG spec sheet.
SPEC · 06
Tooling
Internal tools engineered to be operated; every one title-blocked, versioned, and reproducible.
DRAWN:R.C.F.SSCALE:TRUEREV:2.1.7SHEET:06 OF 08
> 00.7 // PROVENANCE
7.1 Sourced, Measured, Accounted
Not every drawing ships. The ones that do carry a provenance ring: local context, low compute, fully attributed.
[PANEL07/08]
Provenance Rings
100%
Local / On-Device
No cloud round-trip. Authored and rendered where it lives.
0
Tokens Spent
No generative compute on the page. What you read was drawn, not sampled.
92%
Attributed
Every figure, tool, and claim carries a title block back to source.
The footprint is the point: small, deliberate, readable. Every shader runs at half-resolution. Every animation gates behind reduced-motion. No analytics network, no tracking pixel, no third-party script beyond fonts and a single IP geolocation call.
DRAWN:R.C.F.SSCALE:TRUEREV:2.1.7SHEET:07 OF 08
> 00.8 // REFERENCES
8.1 What People Say, Filed
References are drawn as records, not reviews - each title-blocked, each attributed. A drawing set is only as good as what it cites.
[PANEL08/08]
Filed Records
REF·1
The most auditable portfolio I've seen this year. It reads like a spec, not a pitch.
Senior Red Team Lead · Financial Sector
REF·2
Finally someone who treats governance as a drawing you can verify, not a slide deck you trust.
Security Architect · Cloud Platform
REF·3
The dimension lines alone saved us two review meetings. Every engagement should ship with this level of documentation.
Engineering Manager · Internal Tools
DRAWN:R.C.F.SSCALE:TRUEREV:2.1.7SHEET:08 OF 08
Dialog
SYS_CORE // GRC_TERMINAL_NODE
[SHELL: POSIX_SH]
> SESSION // VISITOR SCAN
NET_ID-
GEO-
COORD-
ISP-
UA-
SCREEN-
TZ-
LANG-
CORES-
MEM-
DNT-
COOKIES-
> SCAN PENDING…
Protecting livelihoods against more than social engineering. In an increasingly connected world, cybersecurity is the baseline for human throughput and infrastructure survival. My work centers on network traffic forensics, zero-trust perimeter defense, and operational security across untrusted environments.
Engineering Philosophy & Stance
Zero-Trust Execution - Perimeter defense is dead. Every service connection, endpoint, and packet is untrusted until cryptographically verified.
Global OpSec & Network Hardening - Real-world operational security protecting communications and remote access across 30+ untrusted country networks and 250+ transit environments.
Traffic Forensics & Packet Analysis - Low-level network inspection using packet analyzers and custom scriptable capture tools to isolate threat vectors before escalation.
Creating fair, deterministic rules where there are none. Technical governance is not bureaucratic friction; it is the programmatic codification of ethics, privacy, and compliance directly into software runtime so technology serves human agency.
Engineering Philosophy & Stance
Programmatic Guardrails - Enforcing safety policies and compliance controls directly at the code execution layer rather than relying on manual policy documents.
AI Systems Management (ISO 42001) - Implementing international standards for responsible AI deployment, risk mitigation, and algorithmic accountability.
Privacy & Data Lineage (ISO 27701) - Architecting secure storage and edge ledgers that uphold user privacy management by default.
Engineering resilient internal AI infrastructure that bridges security policy with ground-level machine learning execution. Moving past chatbot wrappers to build production-grade agentic workflows, model routing, and deterministic evaluation harnesses.
Engineering Philosophy & Stance
Deterministic Machine Safety - Guarding non-deterministic neural network outputs with strict schema validation, structured output engines, and evaluation harnesses.
Multi-Agent Orchestration - Architecting stateful, multi-step agent workflows that execute complex tasks reliably without human bottlenecking.
Model Routing & Edge Integration - Balancing cost, speed, and privacy by routing requests across open-weight models and edge runtime workers.
Developing Machine Learning models and data processing pipeline solutions to enhance data analysis, search, and intelligent ranking workflows.
Status
Active Internship · Ongoing
Core Focus
ML Pipeline Development - Building and maintaining scalable data processing pipelines for model training and evaluation.
Model Research & Optimization - Testing and evaluating ML architectures for search relevance, embeddings, and ranking accuracy.
System Integration - Integrating ML service endpoints into production workflows.
Active engagement. Details withheld under NDA. Current focus on backend systems, automation, and internal tooling.
Status
Architected under NDA · Ongoing
Independent educator managing curriculum design, student performance tracking, and high-volume remote instruction for international learners.
Scaled instruction - Delivered live instruction to 100+ students across 10+ countries, adapting pedagogy across CEFR A1–C2.
Performance analytics - Engineered a custom student-tracking framework to monitor KPIs, isolate learning deficiencies, and adjust trajectories in real time.
Structured feedback - Produced post-session analytical reports for 100% of sessions with metric-driven visibility.
High-volume logistics - Managed a peak 52-hour weekly caseload across time zones with 100% attendance compliance.
Outcomes - Guided students to Distinction/140+ KET, Band 7.0–8.0 IELTS, and successful US Student Visa approvals.
Sole operations & technical lead for a globally traveling executive across multiple countries.
Sole IT administrator - End-to-end IT for a mobile executive office; uninterrupted connectivity across 30+ countries and 250+ transit environments.
Network & OpSec - Configured and secured VPN and remote access across 100+ untrusted public networks, protecting comms across 30+ jurisdictions.
Global connectivity - Managed eSIM/SIM provisioning and cross-border cellular configs with 100% uptime for critical comms.
OSINT - Conducted OSINT audits on 500+ service providers and hosts, identifying risk indicators to prevent fraud or safety incidents.
Provided English instruction and cultural exchange across Ukraine, Myanmar, Nepal, and Vietnam - focusing on communities facing economic instability or geopolitical transition.
Geopolitical adaptability - Delivered support in high-tension environments preceding major political shifts, requiring rapid adaptation.
Cross-cultural integration - Bridged linguistic gaps and maintained educational continuity despite external uncertainties.
Resource management - Adapted teaching methods for resource-constrained settings with minimal infrastructure.
Free and open-source citizen tool for mapping, reporting, and visualizing scam network targets in the Philippines. Built from firsthand experience - when family members were targeted by scam operations, the need for an accessible, non-technical reporting tool became personal.
Key features
Scam reporting pipeline - Submit and categorize scam reports with geolocation, contact details, and scam type.
Threat map - Interactive heatmap visualization of reported scam activity clusters across regions, powered by user-submitted data.
Verification workflow - Community-driven verification system to confirm or dispute reports, reducing noise.
Public awareness feed - Timelined display of active scam patterns and warnings visible without authentication.
Client-side browser extension New Tab workspace dashboard. An isolated boot pipeline orchestrates a modular feature loop: CanvasManager for layout asset rendering, GraphManager for D3.v7-driven mathematical data structures, NotesController for local text capture, plus dedicated controllers for Pomodoro tracking, Kanban boards, and a keyboard-commanded terminal interface. Styled via a strict local design-tokens.css framework.
Deep-dive analysis of network-layer vulnerabilities in a controlled lab. Configured a multi-host ARM64 VM and Docker setup simulating a corporate network.
Skills demonstrated
Network traffic analysis - Wireshark & tcpdump to capture and inspect live traffic.
Protocol analysis - Demonstrated a persistent ARP cache poisoning attack.
Packet crafting - Scapy scripts for custom ARP and TCP packets.
MITM simulation - Intercepted and modified a live TCP stream between victim hosts.
WiresharkScapyDockerPython
Independent technical analysis of the XZ Utils supply-chain attack - the social engineering and obfuscation tactics used to compromise the Linux compression library.
Vulnerability research - Dissected the attack vector and how malicious code targeted SSHD authentication.
Threat intelligence - Mapped the multi-year social engineering campaign timeline.
Technical communication - Synthesized findings into an educational presentation.
Supply Chain SecurityThreat Analysis
Gamified, browser-based "Incident Command Center" visualizing the forensic analysis of the 2017 WannaCry ransomware attack.
UI/UX - Custom 8-bit/cyberpunk design system with CRT scanline effects.
Simulation logic - Keyword-driven response logic simulating an AI Incident Commander.
Cybersecurity analysis
Root cause - Exploitation of EternalBlue (SMBv1) and failure to apply MS17-010.
Impact - Quantified the ripple effect across critical infrastructure ($4B+).
Vanilla JSTailwind CSSIncident Response
[One sentence: the problem your team tackled and what you shipped by the deadline.]
My role
[Role] - [What you personally built: the API, the pipeline, the integration.]
Under constraint - [A decision made under time pressure: scope cut, architecture tradeoff, integration hack that worked.]
Outcome
[Placed Nth of N teams / working demo / finalist. Add link if a public artifact exists.]
[Tech 1][Tech 2]Team of [N]
Highest management systems auditing fellowship covering both AI management (ISO/IEC 42001:2023) and privacy information management (ISO/IEC 27701:2025).
ISO/IEC 42001ISO/IEC 27701AI GovernancePrivacy
Lead Auditor certification for Information Security Management Systems (ISMS).
ISMSAudit PlanningRisk Management
Lead Auditor certification for AI Management Systems - the first international standard for AI management.
AI GovernanceAI Risk Management
Lead Auditor certification for Privacy Information Management Systems (PIMS) - the privacy extension to ISO/IEC 27001.
ISO/IEC 27701PrivacyAudit Planning
Two Oracle Cloud Infrastructure 2025 certifications covering core cloud architecture (IaaS, PaaS, SaaS) and the foundational frameworks of AI, ML, and generative AI on OCI.
Rigorous program covering fundamentals of information security, threat modeling, and risk management. Engaging with the global CS50 community directly inspired pursuing Python.
Earned a U.S. high school equivalency diploma with a score of 694, placing in the top 1% of test-takers globally. Achieved through one month of self-directed study across all four subjects.
This portfolio collects minimal telemetry data solely for operational and security auditing purposes, not for advertising or profiling.
Data Collected
IP address & geolocation - Resolved at session level via ipwhois.app. Used to assess regional threat posture. Not logged.
Browser & device fingerprint - GPU renderer, canvas hash, screen resolution, and battery status. Used to detect automation/bot traffic.
Do Not Track signal - Honored. If DNT is enabled, telemetry is reduced to essential-only mode.
Referrer - Source of visit for analytics. Stored ephemerally.
Data Retention & Control
Zero persistent storage - No cookies, no localStorage telemetry logs. Theme preference (`mz-theme`) and opt-out flag (`grc-opt-out`) are the only localStorage entries.
Opt-out - Toggle the TELEMETRY button (bottom-left) to redact all data. The `grc-opt-out` flag is respected before any collection begins.
Third parties - Three.js (via esm.sh), Tailwind CDN, Google Fonts, ipwhois.app. Each operates under their own privacy policy.
Contact
[email protected] - Data subject requests handled within 30 days per GDPR Art. 12.
This website is a personal portfolio presented for professional evaluation. Access constitutes acceptance of the following terms.
Use of Content
Personal portfolio context - All content (text, code samples, certification data) is presented as a representation of professional qualifications. Reproduction for commercial purposes is prohibited.
No warranties - The site is provided "as is" with no guarantees of availability, accuracy, or completeness. The author is not responsible for third-party content linked from this site.
Interactive Features
NLP command palette - The ⌘K terminal accepts natural language queries. No input data is stored or transmitted beyond the client-side NLP parser.
No user accounts - There is no login, no comment system, and no persistent user session beyond the theme preference in localStorage.
Liability
The author shall not be held liable for any damages arising from use of this site or reliance on its content. All technical demonstrations are illustrative and should not be deployed without independent review.
This site operates on a zero-cookie policy for tracking purposes. The only data persisted in your browser is your theme preference.
localStorage Items
mz-theme - Stores your selected theme (sun/moon). No expiration. Cleared via localStorage.removeItem('mz-theme').
grc-opt-out - Stores telemetry opt-out preference. Read before any data collection begins.
Third-Party Requests
assets/tailwind.css - Utility CSS framework (local build, no external requests).
fonts.googleapis.com / fonts.gstatic.com - Font loading. Google's privacy policy applies.
esm.sh - CDN for Three.js. No cookies.
ipwhois.app - IP geolocation (one request per session, 10,000 req/month free with HTTPS). Their rate limits and privacy policy apply.
Managing Preferences
Use the TELEMETRY toggle (bottom-left) to opt out of data collection at any time. No cookie consent banner is displayed because no tracking cookies are used.