Security engineer · Complex systems practitioner

John Menerick

Fourteen years securing Fortune 500 financial institutions, tech companies, startups, and public-sector organizations — applying complex systems science to build defenses that evolve under pressure.

14+
Years in information security
40K+
Endpoints secured via zero trust
78+
Engineers mentored
F500
FinTech, tech, and public sector

Most security programs assume more tools and more operators will keep pace with an ever-expanding attack surface. That assumption is wrong. Defense is a complex adaptive system — one that senses, responds, and evolves.

Drawing on TAME, TOTE feedback loops, and Ashby’s Law of Requisite Variety to engineer security architectures that self-correct under pressure, spanning application security, detection engineering, zero trust, cryptographic protocol design, and AI/ML security.

Core competencies

Application & product security

Threat modeling, secure code review, supply chain

Secure code review, SAST/DAST integration, threat modeling (STRIDE, PASTA, attack trees), secure SDLC design, API security, and supply chain hardening. Built security programs adopted across Fortune 500 SDLC pipelines.

Detection, response & threat intelligence

Detection engineering, SIEM pipelines, forensics

Detection engineering end-to-end, SIEM and telemetry pipeline design, IR and forensics, threat hunting, vulnerability management, and red team automation. Reduced MTTD from hours to minutes at a Fortune 500.

Cryptographic engineering & zero trust

MPC, ZK proofs, TEE, PKI, formal verification

Zero trust and zero-knowledge architecture, MPC, threshold cryptography, SPIFFE/SPIRE, zk-SNARKs and zk-STARKs, BFT/PBFT, Paxos/Raft consensus security, TEE and confidential compute, side-channel mitigation, and formal verification of distributed protocols.

AI/ML security & trusted compute

LLM security, federated learning, autonomous agents

LLM security and prompt injection defense, federated learning security, differential privacy, model poisoning defenses, energy model-driven simulations, autonomous agent security, distributed agent consensus, and verifiable inference in untrusted environments.

Cloud, infrastructure & DevSecOps

AWS/GCP/OCI, CI/CD hardening, service mesh

AWS, GCP, and OCI security architecture, secure CI/CD and IaC hardening, distributed systems security (consistency models, linearizability, causal ordering), container security and service mesh trust, workload orchestration security.

Complex systems science

TAME, TOTE, Ashby’s Law, adaptive defense modeling

Applying the TAME framework, TOTE feedback loops, and Ashby’s Law of Requisite Variety to security architecture. Models the problem before reaching for a tool — mapping feedback loops and failure modes before writing a single detection rule.

Published research & open source

Volunteerism & public service

White House, Office of the President

  • Contributor — Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence
  • Contributor — National Strategy for Trusted Identities in Cyberspace (NSTIC)

DARPA

  • Cyber Grand Challenge finalist
  • AI Cyber Challenge participant

US Department of Defense

  • Satellite contributor
  • InfraGard — US critical infrastructure first responder
  • Alameda County Sheriff’s OES Comm. Team — incident management
CNCF / Kubernetes

Cloud-native security governance

CNCF SIG Security member and Kubernetes SIG Security contributor — working on security standards, threat models, and policy guidance for cloud-native deployments.

OWASP

CFP & CFW review board

Call-for-Papers and Call-for-Workshop reviewer for OWASP conferences, evaluating security research submissions for technical rigor and practitioner relevance.

Cloud Security Alliance

Steering committee member

Contributing to cloud security standards, best practice guidance, and enterprise adoption frameworks.

Conference presenter & lecturer

DEF CON, ISC², CCC, GrrCON, DerbyCon, Skytalks, BSides, RootCon

Invited speaker and lecturer at eight or more major information security conferences spanning offensive security research, supply chain attacks, and AI security architecture.

Accomplishments

DEF CON

Black Badge holder

The most prestigious award in competitive hacking — issued only to winners of DEF CON CTF and select elite competitions. Fewer than a few hundred exist worldwide. A lifetime pass to DEF CON and a permanent mark of elite offensive security capability.

National honor

Tomb of the Unknown Soldier — wreath bearer

Selected as a wreath bearer at Arlington National Cemetery — one of the most solemn honors the United States extends to a civilian, reserved for individuals recognized for distinguished service to the nation.

White House, Office of the President

  • Letter of Recognition for Outstanding Achievements and Merit

US Congress

  • US Senate — Resolution of Merit and Accomplishment
  • US House of Representatives — Resolution of Recognition

Michigan State Senate

  • Resolution of Merit and Accomplishment
Letters of commendation
US Air Force

Distinguished contributions to national security.

US Marine Corps

Distinguished contributions to national security.

US Army

Distinguished contributions to national security.

US Navy

Distinguished contributions to national security.

Certifications

CredentialIssuer
Security professional
Certified Information Systems Security Professional (CISSP)ISC²
InfoSec Assessment Methodology (IAM) I / II / IIINSA
InfoSec Evaluation Methodology (IEM) I / II / IIINSA
Certified Kubernetes Security Specialist (CKS)CNCF
Certified Kubernetes Administrator (CKA)CNCF
SANS elite portfolio (GXPN, GDAT, GX-IA, and others) formerSANS Institute
Google Cloud & infrastructure
Google Cloud Professional CertificationGoogle
Professional Google Workspace AdministratorGoogle
GDC Air-Gapped Security Operator FundamentalsGoogle
SecOps on Google Distributed Cloud — Tier 1 AnalystGoogle
SecOps on Google Distributed Cloud — Tier 2 AnalystGoogle
SecOps on Google Distributed Cloud — Tier 3 AnalystGoogle
Evaluate Your Cloud Next-Generation Firewall NeedsGoogle
Google AI & machine learning
Gemini for Security EngineersGoogle
Machine Learning Operations (MLOps) for Generative AIGoogle
Vector Search and EmbeddingsGoogle
Transformer Models and BERTGoogle
Attention MechanismGoogle
Encoder-Decoder ArchitectureGoogle
Introduction to Generative AIGoogle
Google responsible AI
Responsible AI for Developers: Privacy & SafetyGoogle
Responsible AI for Developers: Fairness & BiasGoogle
Responsible AI: Applying AI Principles with Google CloudGoogle
Introduction to Responsible AIGoogle
Oracle Cloud Infrastructure
OCI Foundations AssociateOracle
OCI AI Foundations AssociateOracle
OCI Data Management Foundations AssociateOracle
Government & federal
IS-100, IS-200, IS-700, IS-800 — Incident Command SystemUS FEMA
Public Trust ClearanceUS Department of Justice / FBI
Other professional
Certified Scrum MasterScrum Alliance
Amateur Extra Class License (W8MEJ)US FCC
General Class & GMRS LicenseUS FCC
LinkedIn Trusted Cryptographic Identity PortfolioLinkedIn

Coding identity & developer rankings

CodersRank profile →

Rankings derived from verified repository activity — not self-reported skills — independently computed from 627,824+ active developers worldwide.

#364
Global rank of 627,824
Top 1%
Worldwide percentile
2,751
CodersRank score
13+
Ranked languages
GigaStreak badge

579 consecutive days of commits

June 29, 2020 to January 28, 2022. CodersRank awards the GigaStreak badge for unbroken daily commit activity measured in hundreds of days. This streak is among the longest verified on the platform — sustained through security tooling, infrastructure automation, and open source research.

579
Consecutive days
Language rankings
LanguageScoreWorld rankUS rankActivity
TypeScript743.2 Top 0.2% of 118KTop 1% of 1K
JavaScript424.8 Top 0.5% of 279KTop 3% of 2K
JSON311.0 Top 0.8% of 283KTop 4% of 2K
HCL206.2 Top 0.7% of 8KTop 3% of 70
Shell172.9 Top 0.2% of 140KTop 1% of 1K
HTML144.2 Top 2% of 292KTop 5% of 2K
CSS / SCSS120.9 / 101.1 Top 2% of 266KTop 4–6%
PHP116.3 Top 4% of 107KTop 5% of 628
Python108.4 Top 5% of 165KTop 9% of 1K
SQL83.7 Top 0.2% of 52KTop 1% of 440
TSQL62.9 Top 0.3% of 55KTop 2% of 395
PLpgSQL54.3 Top 2% of 6KTop 2% of 58
Technology rankings
Node & frontend
Socket.io 0.01% ExpressJS 0.06% NodeJS 0.4% ReactJS 2% Redux Saga 2% Cypress 6% Enzyme 7% Webpack 7% Chai 14% Flask 16% Supertest 18%
Database & backend
node-postgres 8% Fastify 34% MySQL 40% SQLAlchemy 44% PyMongo 52% mongoose 55%
Data science & ML
Pandas 32% SciPy 33% Pytest 46% Sinon 46% PySpark 54% Scikit-Learn 64%

Work philosophy

01

Model before tooling

Maps feedback loops, failure modes, and emergent behavior before writing a single rule.

02

Build what doesn’t exist

Built Gyoithon and IntelMetrics when the tooling wasn’t there. Ships solutions, not vendor evaluations.

03

Operate at both altitudes

Moves between executive architecture conversations and hands-on code review, packet captures, and IR triage in the same week.

04

Teach by doing

Pairs on active incidents and co-authors detections with junior engineers to build genuine systems thinking, not process compliance.

Defaults to transparency — publishing research and open-sourcing tooling so the community can build on it rather than rediscover it.

Perspective

How do you apply complex systems theory to security engineering?

Threat landscapes are nonlinear — attackers adapt, environments shift, controls interact unpredictably. Ashby’s Law of Requisite Variety ensures defensive systems match the adaptive capacity of threats. Practically: detection pipelines with self-tuning feedback loops, architectures where subsystem failure doesn’t cascade, and security operations treated as a living system rather than a fixed-state machine.

What’s missing from how most organizations approach security engineering today?

Three things. First, optimizing for compliance over resilience — while defenders check annual audit boxes, threat actors use AI-driven reconnaissance to compress the attack lifecycle toward near-zero. Second, the velocity gap from underinvestment in automation: without real-time telemetry pipelines and self-healing response workflows, you’re bringing a manual process to a machine-speed fight. Third, failure to treat security as a high-concurrency distributed systems problem. Security has to be a set of algorithmic guarantees, not a gate.

sts:GetCallerIdentity
{
  "id": "ocid1.user.oc1..aaaaaaaaxxxxxxxxxxxxxxxxxxxxxxxx",
  "name": "[email protected]",
  "compartmentId": "ocid1.tenancy.oc1..aaaaaaaayyyyyyyyyyyyyyyyyyyyyyyy",
  "timeCreated": "2024-01-25T15:00:00.000Z",
  "lifecycleState": "ACTIVE"
}

{
  "email": "[email protected]",
  "sub": "117813812345678901234",
  "name": "John Menerick",
  "iss": "https://accounts.google.com"
}