appsec

What I Learned Moving from Security Consulting to Security Engineering

After 16 years in IT and nearly a decade in security consulting, I moved into security engineering. This post is the map I wish I had — what changes, what stays with you, and how the consultant's eye turns out to be the best thing you bring.

semhound

A Python CLI that discovers every repository in one or more GitHub organisations or users, shallow-clones them in parallel, runs your Semgrep rules, and writes a consolidated CSV (and optional SARIF) with permalinks to each finding. Optionally send each finding to Claude, OpenAI, Gemini, or AWS Bedrock for confidence scoring and true-positive triage.