Leveraging four decades of programming experience and years of bootcamp mentoring , he lectures on secure coding in academia and the private sector, leads the OWASP-untrust project, and researches the intersection of AI and application security, with a focus on secure code generation, LLM evaluation, and secure-by-construction development.
He also wrote "Effective Secure Coding, Part I: Building Safer Features".