CONNECTING TO SECTOR 7 // NEO-CI
AUTHENTICATING IDENTITY: M. SCHNEIDER
LOADING ROOFTOP TERMINAL...
▒▒▒▒▒▒▒▒▒▒ ONLINE
SECTOR 7 · ROOFTOP NEO-CI / 2049 --:--:--
USE NEON SIGNS OR ARROW KEYS
Cyberpunk rooftop at night overlooking a city of neon signs
SCHNEIDER
シュナイダー
Dossier · 01
N 41.7° / 90.0°
/// PERSONNEL FILE

DevSecOps in the pipeline.

パ イ プ ラ イ ン ・ セ キ ュ リ テ ィ

I work where code meets policy: embedding security in CI so bad commits fail fast — SAST, SCA, secrets, containers, IaC checks — without turning the pipeline into a paperweight.

Policy-as-code, clear exemptions, and metrics leadership actually reads beat heroics after merge. Earlier depth in SOC and IR means I still speak fluent alert fatigue; today I prefer preventing the incident.

DevSecOpsSASTSCA Secrets scanningSBOM IaC policyContainers MITRE ATT&CKPython
Career · 02
E 89.7° / 41.2°
/// CAREER PIPELINE

Built under pressure.

圧 力 下 で 構 築
Current2026
Software Engineering Intern · Security & Compliance
Bear Robotics
  • Maintain and improve open-source compliance workflows on FOSSlight — process hygiene at engineering scale.
  • Evaluate alternative FOSS compliance tooling; deliver recommendations to replace or improve the stack.
  • Triage SAST findings; escalate critical issues and route ownership to the right teams.
  • Track vulnerabilities from intake through remediation with visible accountability.
  • Reduce manual toil through documentation, automation, and clearer process handoffs.
Current2025
Community Jr. SOC Analyst
Level Effect
  • Real-time alert triage across 100+ student environments — pattern recognition for "noisy but benign."
  • Endpoint forensics and MITRE-mapped incident response; same mental model used to tune CI severity.
Foundation15+ yr
Operations · Incident Response · Reliability
Prior roles
  • Shipped under pressure across operations, IR, and on-call reliability work.
  • Foundation for current focus: gates that catch risk before it ships, not heroics after merge.
Artifacts · 03
S 41.7° / 87.3°
/// SECURITY ENGINEERING ARTIFACTS

Things I've built.

構 築 物 ・ 開 発
FILE_001
Cybersecurity Report Generator
レ ポ ー ト ・ ジ ェ ネ レ ー タ

TypeScript automation that turns IOCs and CVE context into structured incident reports — same "pipeline output" mindset as security tooling in CI.

TypeScript MITRE ATT&CK OpenAI
View on GitHub →
FILE_002
Pipeline Policy Sandbox
ポ リ シ ー ・ サ ン ド ボ ッ ク ス

Local rig for prototyping CI guardrails — SAST/SCA gates, secrets policy, container scanners — before they touch a real repo.

GH Actions OPA Containers
// In progress
FILE_003
SBOM Drift Watch
S B O M ド リ フ ト 監 視

Diffs SBOMs between builds and flags suspicious deltas — silent transitive bumps, unexpected licenses, ghost dependencies.

Python Supply chain CycloneDX
// In progress
Connect · 04
W 41.7° / 92.5°