I built a deliberately vulnerable application, then ran it through a full security pipeline — SAST, SCA, DAST, threat modeling, risk scoring, remediation.
The default scan configuration surfaced 7 of the 18 issues that a local run with custom rules and cross-file analysis found. Same tool, same codebase.
Had I trusted the default, I would have shipped an application I believed was clean. I wrote the whole thing up, and it became a six-part email course.
I build technical email courses for security companies.
Most technical marketing lands in one of two ditches: vendor language with nothing practical in it, or a specification document nobody finishes. I write the thing in between.
I can read your documentation, test the product, and talk to your engineers without marketing having to translate anything first — because this is my day job.
The service
Technical email course
A five-to-seven lesson course for your audience, about your product
You get the strategy, the research, the lessons, and everything needed to launch it:
- Topic and audience strategy, built around one clear reader action
- Product research — documentation, architecture, hands-on testing where access allows
- Five to seven technically reviewed lessons, with code, checklists, or diagrams where they help
- Landing page and welcome email copy
- A closing lesson that leads to a trial, demo, or conversation without reading as a pitch
The shape of it: I learn the product, build the sequence, and hand you publication-ready lessons you can load into your own email platform. Two to three weeks, typically.
See how I build one
Break It, Then Fix It
A free six-part course built from the project above — for developers and security practitioners who want to know what scanners find, what they miss, and how to turn findings into work that actually gets done.
- Why I built something deliberately broken
- What three scanners found — and what the defaults missed
- Threat modeling without the ceremony
- Risk scoring that survives a real backlog
- Remediation, with before-and-after code
- The whole pipeline as a repeatable checklist
One lesson every two days. Free, unsubscribe any time. Sign up and you'll see exactly what I'd build for you.
Who this is for
Companies with a technically strong product and a hard time explaining it to the engineers who'd buy it.
- Application security and software supply-chain vendors
- SAST, SCA, DAST, and ASPM platforms
- Identity, workload-identity, and secrets management
- Cloud security, API security, and platform engineering tools
- Technical marketing agencies with security clients
Selected writing
- Securing the dumbest app I've built — on purposePart 1 · Setup
- What the scanners found before I knew what matteredPart 2 · SAST, SCA, DAST
- Finding creative ways to ruin my own dayPart 3 · Threat modeling
- Not all fires need the fire departmentPart 4 · Risk assessment
- Fixing vulnerabilities like a responsible adultPart 5 · Remediation
- What's the deal with SPIFFE and SPIRE?Explainer · Workload identity
Planning a technical education campaign?
Send me the product, the audience, and what you want readers to do at the end. I'll come back with a course angle and a lesson outline — no charge for that part.
Email me