I feel strongly that security solutions must be balanced with usability; that security in the real world is largely about making good trade-offs and balancing risks. Therefore my work has mostly focused on concrete problems in computer security and building tools that can be used in the real world. This site collects together all of my research and development work in applied security done both as a student and at the NCSA where I started working as a security engineer in 2003.
Currently, I am the NCSA CISO, but I also lead several projects that blend research and development activities. While much of my early research focused upon privacy and data sanitization, I am currently focused most on network security, security architecture and analysis, risk analysis, and developing security plans and policies for federated NSF communities.
For detailed information on past activities and research, please download my curriculum vitae.