JDRC performed architecture, collaborating with senior agency engineers, third-party engineers, and government stakeholders to develop a system capable of ingesting data from multiple camera devices. Designed a modular, reusable architecture that allows many different camera types, output metadata formats, and cloud providers to be quickly integrated. Provided API calls for diagnostics, problem resolution, and statistics to backend software.
The transfer mechanism achieved a near-0% failure rate and surfaced previously undiscovered bugs in third-party software. The resulting software was successfully reused on separate video collection programs.
Served as liaison between units, vendors, and agencies throughout development. Used SAFE agile framework including PI sessions
Software development, upgrades, and bug fixes for a system that replaced a paper-based evidence tracking tool — covering evidence chain of custody, analyst notes, technical and administrative reviews, and digital signatures. Performed database administration, backups, and help desk support, while collaborating with government stakeholders across the country.
Creation of a custom hardware device capable of imaging encrypted electronic devices and transmitting data to analysts. The device included custom, upgradable sections for communications, firmware, and other subsystems, with a custom hot/cold upgrade mechanism and verification tests to prevent bricking. The device was part of a larger ecosystem including load balancers, reverse proxies, and database operations, and required kernel modifications and reverse engineering of established and experimental communication protocols.
Reverse engineering of USB communication protocols for custom imaging product.
Responsible for analyst tools capable of ingesting petabytes of data and surfacing comparisons and connections between entities — allowing analysts to quickly review associations. Data was shared across partner agency teams, with dedicated data visualization support.
DevSecOps operations including CI/CD pipelines and automated Git integration and test. Used SAFE agile framework including PI sessions, sprints, and planning sessions. Scalable architecture including Docker Containers, Kubernetes clusters, etc. Used microservice architecture and RabbitMQ for communications.
Architected, developed, and demonstrated solutions for new and one-off customer requirements, moving quickly from concept to a working proof-of-concept. Where a prototype proved out a real operational need, transformed the minimum viable product into a fully supported, enterprise-grade application — carrying lessons learned from the prototyping phase forward into production-ready architecture, testing, and documentation.
Designed embedded firmware to control custom hardware built for specific real-world operational scenarios. Work spanned low-level hardware and software interfacing, digital logic design, and firmware tuned to the constraints of purpose-built devices — carried from initial concept through field-ready implementation.
Designed and maintained data architecture across the application lifecycle, from schema design through long-term maintenance. Built and maintained ORM mappings to keep application code and the underlying database schema in sync, and planned and executed schema upgrades and migrations with minimal downtime and no data loss. Work spanned normalization, indexing, and query performance tuning to keep growing datasets fast and reliable as requirements evolved.
Performed hardware and software reverse engineering using tools such as Frida for dynamic instrumentation and Ghidra for static binary analysis, working to understand undocumented systems, protocols, and embedded devices. Collaborated closely with mission partners throughout each engagement — sharing new techniques, troubleshooting dead ends, and iterating on approaches as new challenges surfaced.
Provided ongoing support across multiple enterprise projects, incorporating new feature requirements, resolving bugs, and performing database updates as systems evolved. Delivered on-call support for field offices across the United States, ensuring mission-critical software remained available and reliable for end users nationwide.
Built a secure mechanism allowing analysts to extract specific data from low-side systems, transfer it to the high side, and incorporate it directly into automated analytical tools. The effort included visits to multiple field offices and direct conversations with end users to ensure the tooling matched real analyst workflows.
Integrated C# application code directly with Microsoft Azure cloud services, including Azure Key Vault for secrets and credential management, Azure Identity for authentication and role-based access control, and Azure-based data transfer pipelines for secure movement of data between on-premises systems and the cloud. This embedded approach allowed cloud security and identity primitives to be woven directly into the application layer rather than bolted on as a separate service.
Delivered full-stack development across the entire application stack — from backend business logic and database transaction handling to front-end page design and implementation. Built and consumed RESTful and internal API calls to connect services and share data reliably across systems, and integrated commercial off-the-shelf (COTS) software into custom applications, bridging third-party tools with in-house systems to meet enterprise requirements.
Supported the Operations and Radio Frequency (RF) countermeasures sections to research, design, develop, and modify in-house software, staying current on emerging threats through ongoing intelligence reporting and researching and proposing software solutions to counter them. Collaborated with field users from design through implementation of in-house developed software, and worked closely with technicians and hardware engineers to develop innovative software solutions.
Focused on the research and development of equipment required to detect and locate threats posed to the U.S. Government by emerging technologies, partnering with other Department of State organizations to understand vulnerabilities associated with GSM, GPRS, CDMA, IEEE 802.15, IEEE 802.11a/b/g/n/ac (Wi-Fi), Bluetooth, Zigbee, and Z-Wave.
Participated in working groups and policy boards, reviewing and commenting on draft and modified policy documents — including Foreign Affairs Handbooks and Manuals (FAHs/FAMs), National Institute of Standards and Technology (NIST) publications, and Committee on National Security Systems Instructions (CNSSI) — providing in-depth analysis of the feasibility and cost-effectiveness of proposed policies and flagging areas of potential conflict with existing Department, OSPB, or other federal agency policy and guidance.
Supported Department activities involving countermeasures equipment for facility inspections, and developed and maintained a countermeasures equipment arsenal to meet new and evolving threats and technologies in telecommunications security and research technology. Collaborated with other bureaus and agencies to effectively address new technology and its associated threats.
Identified, reviewed, evaluated, and recommended new, updated, and promising Technical Surveillance Countermeasures (TSCM) and non-destructive testing and evaluation (NDT&E) systems and instrumentation to address known issues and vulnerabilities, developing new operational procedures and training material to support programmatic application. Responsibilities included identifying system vulnerabilities and mitigation strategies, monitoring and analyzing the electromagnetic environment for technical threats and anomalies, identifying potential technical surveillance activities against Department computer hardware and peripherals, and applying new detection technologies and techniques to both general and specific security problems.
Supported the TSCM Radio Frequency (RF) Monitoring Program, which develops, installs, and maintains highly sophisticated, cost-effective RF platforms at diplomatic facilities worldwide, detecting, analyzing, exploiting, neutralizing, and deterring hostile electromagnetic and RF threats and other technical hazards. Also supported the Emanations Countermeasures Branch (ECB) in protecting classified information by specifying, designing, reviewing, installing, testing, and maintaining electromagnetic and acoustic countermeasures for domestic and overseas U.S. missions.
Supported the Technology Evaluation Branch (TEB) in protecting sensitive and classified information processed on mobile and fixed information technologies — including smartphones, tablets, laptops, workstations, printers, and network hardware — by identifying and evaluating new information and telecommunications technologies. Investigated technical security vulnerabilities of emerging IT, with a focus on inherent hardware-based vulnerabilities and available mitigation strategies, including for commercial-off-the-shelf (COTS) IT with embedded RF wireless transmitters. Configured and tested mobile portable electronic devices (BlackBerry, Apple iOS, Android) and made Mobile Device Management (MDM) configuration recommendations, including BlackBerry Enterprise Server and Citrix XenMobile.
Investigated and evaluated new information and telecommunications technologies to identify hardware-based vulnerabilities and develop secure-use mitigation strategies. Conceived testing procedures and protocols, drafted and finalized approved test plans, and documented investigation results in final reports suitable for Department management. Based on test results, framed and fully documented mitigation strategies necessary for the secure use of evaluated hardware.
Performed a liaison function with other U.S. Government agencies and departments and International Technical Security Exchange (INTECSEC) community partners. Identified and investigated new and emerging information and telecommunications technologies for suitability in transmitting and processing sensitive and classified national security information, and performed technical vulnerability analyses of proposed COTS IT office and mobile workforce products such as BlackBerry Enterprise Server and Citrix XenMobile.
Developed documentation on hardware-focused evaluations of submitted technologies, including Wireless Intrusion Detection Systems, Mobile Device Management applications, wireless internet implementation within domestic facilities, and Secret Voice over Internet Protocol (VoIP), and liaised with other USG agencies and INTECSEC community members to prevent duplication of effort.
Developed reports based on the collection and analysis of technical security and event information, and represented the Department on interagency technical surveillance threat issues. Staffed the Technical Operations Group (TOG) at the DS Command Center and conducted risk assessments of posts and facilities to support technical surveillance countermeasures decisions.
Provided Department management with a quantitative method for selecting technical countermeasures based on calculated risk, cost-benefit, and operational impact, using the Analytical Risk Management (ARM) methodology to profile a mission's technical threat level, asset importance, and technical vulnerabilities and countermeasures.
Developed, maintained, and updated common-use tools for collecting information critical to risk and threat analysis activities. Gathered, analyzed, and managed evolving tool requirements, and investigated alternative program design approaches to determine the best-balanced solution across enterprise software applications and databases. Collected data from multiple sources and platforms, analyzed relationships between entities, and developed intelligent, IT-based tools that integrated this data into products directly useful to the analysis process.