View J8k3's full-sized avatar
💭
Building things. Writing about it at jacobmarks.com.
💭
Building things. Writing about it at jacobmarks.com.

Block or report J8k3

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
J8k3/README.md

Jacob Marks

Senior Engineering Leader | Payment Cryptography | Distributed Systems | ex-AWS

I build and scale security-critical, regulated infrastructure where correctness, compliance, and availability are non-negotiable. Most recently I led the architecture and launch of AWS Payment Cryptography, a globally deployed, hardware-backed cryptographic service, taking it from ambiguous customer input to production under strict PCI and regulatory constraints.

I operate at the boundary between deep technical design and durable execution: defining systems, authoring threat models, governing hardware and software designs, and building the operational practices that hold up over time. I stay hands-on in critical paths and set technical direction that scales beyond my direct involvement.

Currently targeting Director of Engineering, VP Engineering, or senior IC roles in fintech, payments, and security-critical infrastructure.

📄 Blog & Website · 💼 LinkedIn


🔧 Active Projects

CyberChef Payments

J8k3/CyberChef · J8k3/CyberChef-Payments, AI-assisted development

A fork of GCHQ's CyberChef extended with payment cryptography tooling for engineering, debugging, interoperability testing, and standards exploration. If you've done this work in payments you know the time it takes to test schemes and data structures without a live HSM. That's the gap this fills.

J8k3/CyberChef — the implementation fork. Operations cover EMV (ARQC/ARPC, issuer scripts, MAC), PIN (blocks, DUKPT TDES/AES, IBM 3624, Visa PVV), MAC, card validation, key management (TR-31, TR-34, ECDH, KCV), and HSM command parsing (Thales payShield, Futurex). All operations are explicit, inspectable, and composable. Fully client-side, nothing leaves your browser.

J8k3/CyberChef-Payments — workflow catalog with recipe links, screenshots, chaining patterns, and validation status across all operations.

🌐 Live demo: cyberchef.jacobmarks.com

AWS Payment Cryptography HSM Proxy

J8k3/aws-payment-cryptography-hsm-proxy, AI-assisted development

A local proxy that speaks the wire protocols of physical payment HSMs (Thales payShield, Futurex Excrypt) and maps them onto AWS Payment Cryptography, so existing payment applications, test harnesses, and integrations keep working without rewriting against the AWS SDK. The goal is portability rather than one-way migration: your application talks to a stable HSM-style interface while the platform behind it can change, creating interoperability across payment HSM platforms instead of locking you to any single one.

AWS Payment Cryptography MCP

J8k3/aws-payment-cryptography-mcp, AI-assisted development

A Model Context Protocol server for AWS Payment Cryptography. Companion to the HSM proxy. Exposes APC operations as MCP tools so LLM-driven agents and assistants can perform structured payment cryptography work with proper boundaries.


🏗️ Engineering Background

AWS Payment Cryptography (2021–2026)

Led the definition, architecture, and launch of a globally deployed, hardware-backed cryptography-as-a-service platform, a first of its kind in the cloud.

  • Authored the foundational threat model and security posture from early customer input through launch and steady-state
  • Defined and governed control-plane, data-plane, and hardware designs, maintaining system coherence through technical review
  • Established operational and observability practices focused on customer impact and failure modes
  • Introduced daily HSM fleet health evaluation, reducing unsellable capacity from ~10% toward ~5%
  • Established hardware-backed design patterns later reused across related cryptographic services

EC2 Core Platform (2018–2021)

Owned core EC2 platform services and led architectural improvements at massive scale.

  • Led architectural separation of telemetry and billing systems supporting hundreds of petabytes of customer data
  • Owned platform-level reliability and cost tradeoffs across core EC2 infrastructure during periods of rapid scale

Defense & National Security (Booz Allen Hamilton, 2008–2016)

Progressed from hands-on engineer into technical and program leadership on systems operating under security and compliance constraints.


🛠️ Technical Depth

  • Languages: C# / .NET (primary), Javascript, Python, Rust
  • Domains: Payment cryptography, HSM/PCI compliance, distributed systems, key management, cloud infrastructure
  • Security: Threat modeling, PCI-DSS, NIST/DoD ATO, hardware security modules
  • Leadership: Multi-team engineering orgs, technical direction, engineering management

📁 Other Projects

  • aws-ms-deploy-assistant, AWS Labs project (contributions under legacy account @J8K3-zz)
  • LightningPDF, fast-loading PDF viewer with merge, rotate, and reorder features; built for speed when reviewing large document volumes (C#)
  • document-sorter, PDF document classifier that automatically organizes scanned documents into folders based on keyword matching rules (C#)
  • awssescredgen, CLI tooling for AWS SES credential generation (C#)
  • speventreceiverman, utility for SharePoint event receiver management (C#)

Note on GitHub accounts: Due to a legacy account recovery issue, my original profile was renamed by GitHub. Current active account: @J8k3. Historical contributions: @J8K3-zz.

Pinned Loading

  1. CyberChefCyberChefPublic

    Forked from gchq/CyberChef

    This fork extends CyberChef with a focused set of payment cryptography operations intended for engineering, debugging, and interoperability work in regulated payment environments.

    JavaScript 2

  2. aws-payment-cryptography-hsm-proxyaws-payment-cryptography-hsm-proxyPublic

    Rust TCP proxy: translate Thales payShield 10K and Futurex Excrypt wire commands to AWS Payment Cryptography API calls, without changing the application.

    Rust 2

  3. aws-payment-cryptography-mcpaws-payment-cryptography-mcpPublic

    MCP server for AWS Payment Cryptography — key lifecycle, HSM migration analysis, and PCI-aware cryptographic operations. Works with Claude Code, Codex CLI, and any MCP-compatible client.

    Python 1

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
View J8k3's full-sized avatar
💭
Building things. Writing about it at jacobmarks.com.
💭
Building things. Writing about it at jacobmarks.com.

Block or report J8k3

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
J8k3/README.md

Jacob Marks

Senior Engineering Leader | Payment Cryptography | Distributed Systems | ex-AWS

I build and scale security-critical, regulated infrastructure where correctness, compliance, and availability are non-negotiable. Most recently I led the architecture and launch of AWS Payment Cryptography, a globally deployed, hardware-backed cryptographic service, taking it from ambiguous customer input to production under strict PCI and regulatory constraints.

I operate at the boundary between deep technical design and durable execution: defining systems, authoring threat models, governing hardware and software designs, and building the operational practices that hold up over time. I stay hands-on in critical paths and set technical direction that scales beyond my direct involvement.

Currently targeting Director of Engineering, VP Engineering, or senior IC roles in fintech, payments, and security-critical infrastructure.

📄 Blog & Website · 💼 LinkedIn


🔧 Active Projects

CyberChef Payments

J8k3/CyberChef · J8k3/CyberChef-Payments, AI-assisted development

A fork of GCHQ's CyberChef extended with payment cryptography tooling for engineering, debugging, interoperability testing, and standards exploration. If you've done this work in payments you know the time it takes to test schemes and data structures without a live HSM. That's the gap this fills.

J8k3/CyberChef — the implementation fork. Operations cover EMV (ARQC/ARPC, issuer scripts, MAC), PIN (blocks, DUKPT TDES/AES, IBM 3624, Visa PVV), MAC, card validation, key management (TR-31, TR-34, ECDH, KCV), and HSM command parsing (Thales payShield, Futurex). All operations are explicit, inspectable, and composable. Fully client-side, nothing leaves your browser.

J8k3/CyberChef-Payments — workflow catalog with recipe links, screenshots, chaining patterns, and validation status across all operations.

🌐 Live demo: cyberchef.jacobmarks.com

AWS Payment Cryptography HSM Proxy

J8k3/aws-payment-cryptography-hsm-proxy, AI-assisted development

A local proxy that speaks the wire protocols of physical payment HSMs (Thales payShield, Futurex Excrypt) and maps them onto AWS Payment Cryptography, so existing payment applications, test harnesses, and integrations keep working without rewriting against the AWS SDK. The goal is portability rather than one-way migration: your application talks to a stable HSM-style interface while the platform behind it can change, creating interoperability across payment HSM platforms instead of locking you to any single one.

AWS Payment Cryptography MCP

J8k3/aws-payment-cryptography-mcp, AI-assisted development

A Model Context Protocol server for AWS Payment Cryptography. Companion to the HSM proxy. Exposes APC operations as MCP tools so LLM-driven agents and assistants can perform structured payment cryptography work with proper boundaries.


🏗️ Engineering Background

AWS Payment Cryptography (2021–2026)

Led the definition, architecture, and launch of a globally deployed, hardware-backed cryptography-as-a-service platform, a first of its kind in the cloud.

  • Authored the foundational threat model and security posture from early customer input through launch and steady-state
  • Defined and governed control-plane, data-plane, and hardware designs, maintaining system coherence through technical review
  • Established operational and observability practices focused on customer impact and failure modes
  • Introduced daily HSM fleet health evaluation, reducing unsellable capacity from ~10% toward ~5%
  • Established hardware-backed design patterns later reused across related cryptographic services

EC2 Core Platform (2018–2021)

Owned core EC2 platform services and led architectural improvements at massive scale.

  • Led architectural separation of telemetry and billing systems supporting hundreds of petabytes of customer data
  • Owned platform-level reliability and cost tradeoffs across core EC2 infrastructure during periods of rapid scale

Defense & National Security (Booz Allen Hamilton, 2008–2016)

Progressed from hands-on engineer into technical and program leadership on systems operating under security and compliance constraints.


🛠️ Technical Depth

  • Languages: C# / .NET (primary), Javascript, Python, Rust
  • Domains: Payment cryptography, HSM/PCI compliance, distributed systems, key management, cloud infrastructure
  • Security: Threat modeling, PCI-DSS, NIST/DoD ATO, hardware security modules
  • Leadership: Multi-team engineering orgs, technical direction, engineering management

📁 Other Projects

  • aws-ms-deploy-assistant, AWS Labs project (contributions under legacy account @J8K3-zz)
  • LightningPDF, fast-loading PDF viewer with merge, rotate, and reorder features; built for speed when reviewing large document volumes (C#)
  • document-sorter, PDF document classifier that automatically organizes scanned documents into folders based on keyword matching rules (C#)
  • awssescredgen, CLI tooling for AWS SES credential generation (C#)
  • speventreceiverman, utility for SharePoint event receiver management (C#)

Note on GitHub accounts: Due to a legacy account recovery issue, my original profile was renamed by GitHub. Current active account: @J8k3. Historical contributions: @J8K3-zz.

Pinned Loading

  1. CyberChefCyberChefPublic

    Forked from gchq/CyberChef

    This fork extends CyberChef with a focused set of payment cryptography operations intended for engineering, debugging, and interoperability work in regulated payment environments.

    JavaScript 2

  2. aws-payment-cryptography-hsm-proxyaws-payment-cryptography-hsm-proxyPublic

    Rust TCP proxy: translate Thales payShield 10K and Futurex Excrypt wire commands to AWS Payment Cryptography API calls, without changing the application.

    Rust 2

  3. aws-payment-cryptography-mcpaws-payment-cryptography-mcpPublic

    MCP server for AWS Payment Cryptography — key lifecycle, HSM migration analysis, and PCI-aware cryptographic operations. Works with Claude Code, Codex CLI, and any MCP-compatible client.

    Python 1

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
View J8k3's full-sized avatar
💭
Building things. Writing about it at jacobmarks.com.
💭
Building things. Writing about it at jacobmarks.com.

Block or report J8k3

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
J8k3/README.md

Jacob Marks

Senior Engineering Leader | Payment Cryptography | Distributed Systems | ex-AWS

I build and scale security-critical, regulated infrastructure where correctness, compliance, and availability are non-negotiable. Most recently I led the architecture and launch of AWS Payment Cryptography, a globally deployed, hardware-backed cryptographic service, taking it from ambiguous customer input to production under strict PCI and regulatory constraints.

I operate at the boundary between deep technical design and durable execution: defining systems, authoring threat models, governing hardware and software designs, and building the operational practices that hold up over time. I stay hands-on in critical paths and set technical direction that scales beyond my direct involvement.

Currently targeting Director of Engineering, VP Engineering, or senior IC roles in fintech, payments, and security-critical infrastructure.

📄 Blog & Website · 💼 LinkedIn


🔧 Active Projects

CyberChef Payments

J8k3/CyberChef · J8k3/CyberChef-Payments, AI-assisted development

A fork of GCHQ's CyberChef extended with payment cryptography tooling for engineering, debugging, interoperability testing, and standards exploration. If you've done this work in payments you know the time it takes to test schemes and data structures without a live HSM. That's the gap this fills.

J8k3/CyberChef — the implementation fork. Operations cover EMV (ARQC/ARPC, issuer scripts, MAC), PIN (blocks, DUKPT TDES/AES, IBM 3624, Visa PVV), MAC, card validation, key management (TR-31, TR-34, ECDH, KCV), and HSM command parsing (Thales payShield, Futurex). All operations are explicit, inspectable, and composable. Fully client-side, nothing leaves your browser.

J8k3/CyberChef-Payments — workflow catalog with recipe links, screenshots, chaining patterns, and validation status across all operations.

🌐 Live demo: cyberchef.jacobmarks.com

AWS Payment Cryptography HSM Proxy

J8k3/aws-payment-cryptography-hsm-proxy, AI-assisted development

A local proxy that speaks the wire protocols of physical payment HSMs (Thales payShield, Futurex Excrypt) and maps them onto AWS Payment Cryptography, so existing payment applications, test harnesses, and integrations keep working without rewriting against the AWS SDK. The goal is portability rather than one-way migration: your application talks to a stable HSM-style interface while the platform behind it can change, creating interoperability across payment HSM platforms instead of locking you to any single one.

AWS Payment Cryptography MCP

J8k3/aws-payment-cryptography-mcp, AI-assisted development

A Model Context Protocol server for AWS Payment Cryptography. Companion to the HSM proxy. Exposes APC operations as MCP tools so LLM-driven agents and assistants can perform structured payment cryptography work with proper boundaries.


🏗️ Engineering Background

AWS Payment Cryptography (2021–2026)

Led the definition, architecture, and launch of a globally deployed, hardware-backed cryptography-as-a-service platform, a first of its kind in the cloud.

  • Authored the foundational threat model and security posture from early customer input through launch and steady-state
  • Defined and governed control-plane, data-plane, and hardware designs, maintaining system coherence through technical review
  • Established operational and observability practices focused on customer impact and failure modes
  • Introduced daily HSM fleet health evaluation, reducing unsellable capacity from ~10% toward ~5%
  • Established hardware-backed design patterns later reused across related cryptographic services

EC2 Core Platform (2018–2021)

Owned core EC2 platform services and led architectural improvements at massive scale.

  • Led architectural separation of telemetry and billing systems supporting hundreds of petabytes of customer data
  • Owned platform-level reliability and cost tradeoffs across core EC2 infrastructure during periods of rapid scale

Defense & National Security (Booz Allen Hamilton, 2008–2016)

Progressed from hands-on engineer into technical and program leadership on systems operating under security and compliance constraints.


🛠️ Technical Depth

  • Languages: C# / .NET (primary), Javascript, Python, Rust
  • Domains: Payment cryptography, HSM/PCI compliance, distributed systems, key management, cloud infrastructure
  • Security: Threat modeling, PCI-DSS, NIST/DoD ATO, hardware security modules
  • Leadership: Multi-team engineering orgs, technical direction, engineering management

📁 Other Projects

  • aws-ms-deploy-assistant, AWS Labs project (contributions under legacy account @J8K3-zz)
  • LightningPDF, fast-loading PDF viewer with merge, rotate, and reorder features; built for speed when reviewing large document volumes (C#)
  • document-sorter, PDF document classifier that automatically organizes scanned documents into folders based on keyword matching rules (C#)
  • awssescredgen, CLI tooling for AWS SES credential generation (C#)
  • speventreceiverman, utility for SharePoint event receiver management (C#)

Note on GitHub accounts: Due to a legacy account recovery issue, my original profile was renamed by GitHub. Current active account: @J8k3. Historical contributions: @J8K3-zz.

Pinned Loading

  1. CyberChefCyberChefPublic

    Forked from gchq/CyberChef

    This fork extends CyberChef with a focused set of payment cryptography operations intended for engineering, debugging, and interoperability work in regulated payment environments.

    JavaScript 2

  2. aws-payment-cryptography-hsm-proxyaws-payment-cryptography-hsm-proxyPublic

    Rust TCP proxy: translate Thales payShield 10K and Futurex Excrypt wire commands to AWS Payment Cryptography API calls, without changing the application.

    Rust 2

  3. aws-payment-cryptography-mcpaws-payment-cryptography-mcpPublic

    MCP server for AWS Payment Cryptography — key lifecycle, HSM migration analysis, and PCI-aware cryptographic operations. Works with Claude Code, Codex CLI, and any MCP-compatible client.

    Python 1

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
View J8k3's full-sized avatar
💭
Building things. Writing about it at jacobmarks.com.
💭
Building things. Writing about it at jacobmarks.com.

Block or report J8k3

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
J8k3/README.md

Jacob Marks

Senior Engineering Leader | Payment Cryptography | Distributed Systems | ex-AWS

I build and scale security-critical, regulated infrastructure where correctness, compliance, and availability are non-negotiable. Most recently I led the architecture and launch of AWS Payment Cryptography, a globally deployed, hardware-backed cryptographic service, taking it from ambiguous customer input to production under strict PCI and regulatory constraints.

I operate at the boundary between deep technical design and durable execution: defining systems, authoring threat models, governing hardware and software designs, and building the operational practices that hold up over time. I stay hands-on in critical paths and set technical direction that scales beyond my direct involvement.

Currently targeting Director of Engineering, VP Engineering, or senior IC roles in fintech, payments, and security-critical infrastructure.

📄 Blog & Website · 💼 LinkedIn


🔧 Active Projects

CyberChef Payments

J8k3/CyberChef · J8k3/CyberChef-Payments, AI-assisted development

A fork of GCHQ's CyberChef extended with payment cryptography tooling for engineering, debugging, interoperability testing, and standards exploration. If you've done this work in payments you know the time it takes to test schemes and data structures without a live HSM. That's the gap this fills.

J8k3/CyberChef — the implementation fork. Operations cover EMV (ARQC/ARPC, issuer scripts, MAC), PIN (blocks, DUKPT TDES/AES, IBM 3624, Visa PVV), MAC, card validation, key management (TR-31, TR-34, ECDH, KCV), and HSM command parsing (Thales payShield, Futurex). All operations are explicit, inspectable, and composable. Fully client-side, nothing leaves your browser.

J8k3/CyberChef-Payments — workflow catalog with recipe links, screenshots, chaining patterns, and validation status across all operations.

🌐 Live demo: cyberchef.jacobmarks.com

AWS Payment Cryptography HSM Proxy

J8k3/aws-payment-cryptography-hsm-proxy, AI-assisted development

A local proxy that speaks the wire protocols of physical payment HSMs (Thales payShield, Futurex Excrypt) and maps them onto AWS Payment Cryptography, so existing payment applications, test harnesses, and integrations keep working without rewriting against the AWS SDK. The goal is portability rather than one-way migration: your application talks to a stable HSM-style interface while the platform behind it can change, creating interoperability across payment HSM platforms instead of locking you to any single one.

AWS Payment Cryptography MCP

J8k3/aws-payment-cryptography-mcp, AI-assisted development

A Model Context Protocol server for AWS Payment Cryptography. Companion to the HSM proxy. Exposes APC operations as MCP tools so LLM-driven agents and assistants can perform structured payment cryptography work with proper boundaries.


🏗️ Engineering Background

AWS Payment Cryptography (2021–2026)

Led the definition, architecture, and launch of a globally deployed, hardware-backed cryptography-as-a-service platform, a first of its kind in the cloud.

  • Authored the foundational threat model and security posture from early customer input through launch and steady-state
  • Defined and governed control-plane, data-plane, and hardware designs, maintaining system coherence through technical review
  • Established operational and observability practices focused on customer impact and failure modes
  • Introduced daily HSM fleet health evaluation, reducing unsellable capacity from ~10% toward ~5%
  • Established hardware-backed design patterns later reused across related cryptographic services

EC2 Core Platform (2018–2021)

Owned core EC2 platform services and led architectural improvements at massive scale.

  • Led architectural separation of telemetry and billing systems supporting hundreds of petabytes of customer data
  • Owned platform-level reliability and cost tradeoffs across core EC2 infrastructure during periods of rapid scale

Defense & National Security (Booz Allen Hamilton, 2008–2016)

Progressed from hands-on engineer into technical and program leadership on systems operating under security and compliance constraints.


🛠️ Technical Depth

  • Languages: C# / .NET (primary), Javascript, Python, Rust
  • Domains: Payment cryptography, HSM/PCI compliance, distributed systems, key management, cloud infrastructure
  • Security: Threat modeling, PCI-DSS, NIST/DoD ATO, hardware security modules
  • Leadership: Multi-team engineering orgs, technical direction, engineering management

📁 Other Projects

  • aws-ms-deploy-assistant, AWS Labs project (contributions under legacy account @J8K3-zz)
  • LightningPDF, fast-loading PDF viewer with merge, rotate, and reorder features; built for speed when reviewing large document volumes (C#)
  • document-sorter, PDF document classifier that automatically organizes scanned documents into folders based on keyword matching rules (C#)
  • awssescredgen, CLI tooling for AWS SES credential generation (C#)
  • speventreceiverman, utility for SharePoint event receiver management (C#)

Note on GitHub accounts: Due to a legacy account recovery issue, my original profile was renamed by GitHub. Current active account: @J8k3. Historical contributions: @J8K3-zz.

Pinned Loading

  1. CyberChefCyberChefPublic

    Forked from gchq/CyberChef

    This fork extends CyberChef with a focused set of payment cryptography operations intended for engineering, debugging, and interoperability work in regulated payment environments.

    JavaScript 2

  2. aws-payment-cryptography-hsm-proxyaws-payment-cryptography-hsm-proxyPublic

    Rust TCP proxy: translate Thales payShield 10K and Futurex Excrypt wire commands to AWS Payment Cryptography API calls, without changing the application.

    Rust 2

  3. aws-payment-cryptography-mcpaws-payment-cryptography-mcpPublic

    MCP server for AWS Payment Cryptography — key lifecycle, HSM migration analysis, and PCI-aware cryptographic operations. Works with Claude Code, Codex CLI, and any MCP-compatible client.

    Python 1

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
View J8k3's full-sized avatar
💭
Building things. Writing about it at jacobmarks.com.
💭
Building things. Writing about it at jacobmarks.com.

Block or report J8k3

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
J8k3/README.md

Jacob Marks

Senior Engineering Leader | Payment Cryptography | Distributed Systems | ex-AWS

I build and scale security-critical, regulated infrastructure where correctness, compliance, and availability are non-negotiable. Most recently I led the architecture and launch of AWS Payment Cryptography, a globally deployed, hardware-backed cryptographic service, taking it from ambiguous customer input to production under strict PCI and regulatory constraints.

I operate at the boundary between deep technical design and durable execution: defining systems, authoring threat models, governing hardware and software designs, and building the operational practices that hold up over time. I stay hands-on in critical paths and set technical direction that scales beyond my direct involvement.

Currently targeting Director of Engineering, VP Engineering, or senior IC roles in fintech, payments, and security-critical infrastructure.

📄 Blog & Website · 💼 LinkedIn


🔧 Active Projects

CyberChef Payments

J8k3/CyberChef · J8k3/CyberChef-Payments, AI-assisted development

A fork of GCHQ's CyberChef extended with payment cryptography tooling for engineering, debugging, interoperability testing, and standards exploration. If you've done this work in payments you know the time it takes to test schemes and data structures without a live HSM. That's the gap this fills.

J8k3/CyberChef — the implementation fork. Operations cover EMV (ARQC/ARPC, issuer scripts, MAC), PIN (blocks, DUKPT TDES/AES, IBM 3624, Visa PVV), MAC, card validation, key management (TR-31, TR-34, ECDH, KCV), and HSM command parsing (Thales payShield, Futurex). All operations are explicit, inspectable, and composable. Fully client-side, nothing leaves your browser.

J8k3/CyberChef-Payments — workflow catalog with recipe links, screenshots, chaining patterns, and validation status across all operations.

🌐 Live demo: cyberchef.jacobmarks.com

AWS Payment Cryptography HSM Proxy

J8k3/aws-payment-cryptography-hsm-proxy, AI-assisted development

A local proxy that speaks the wire protocols of physical payment HSMs (Thales payShield, Futurex Excrypt) and maps them onto AWS Payment Cryptography, so existing payment applications, test harnesses, and integrations keep working without rewriting against the AWS SDK. The goal is portability rather than one-way migration: your application talks to a stable HSM-style interface while the platform behind it can change, creating interoperability across payment HSM platforms instead of locking you to any single one.

AWS Payment Cryptography MCP

J8k3/aws-payment-cryptography-mcp, AI-assisted development

A Model Context Protocol server for AWS Payment Cryptography. Companion to the HSM proxy. Exposes APC operations as MCP tools so LLM-driven agents and assistants can perform structured payment cryptography work with proper boundaries.


🏗️ Engineering Background

AWS Payment Cryptography (2021–2026)

Led the definition, architecture, and launch of a globally deployed, hardware-backed cryptography-as-a-service platform, a first of its kind in the cloud.

  • Authored the foundational threat model and security posture from early customer input through launch and steady-state
  • Defined and governed control-plane, data-plane, and hardware designs, maintaining system coherence through technical review
  • Established operational and observability practices focused on customer impact and failure modes
  • Introduced daily HSM fleet health evaluation, reducing unsellable capacity from ~10% toward ~5%
  • Established hardware-backed design patterns later reused across related cryptographic services

EC2 Core Platform (2018–2021)

Owned core EC2 platform services and led architectural improvements at massive scale.

  • Led architectural separation of telemetry and billing systems supporting hundreds of petabytes of customer data
  • Owned platform-level reliability and cost tradeoffs across core EC2 infrastructure during periods of rapid scale

Defense & National Security (Booz Allen Hamilton, 2008–2016)

Progressed from hands-on engineer into technical and program leadership on systems operating under security and compliance constraints.


🛠️ Technical Depth

  • Languages: C# / .NET (primary), Javascript, Python, Rust
  • Domains: Payment cryptography, HSM/PCI compliance, distributed systems, key management, cloud infrastructure
  • Security: Threat modeling, PCI-DSS, NIST/DoD ATO, hardware security modules
  • Leadership: Multi-team engineering orgs, technical direction, engineering management

📁 Other Projects

  • aws-ms-deploy-assistant, AWS Labs project (contributions under legacy account @J8K3-zz)
  • LightningPDF, fast-loading PDF viewer with merge, rotate, and reorder features; built for speed when reviewing large document volumes (C#)
  • document-sorter, PDF document classifier that automatically organizes scanned documents into folders based on keyword matching rules (C#)
  • awssescredgen, CLI tooling for AWS SES credential generation (C#)
  • speventreceiverman, utility for SharePoint event receiver management (C#)

Note on GitHub accounts: Due to a legacy account recovery issue, my original profile was renamed by GitHub. Current active account: @J8k3. Historical contributions: @J8K3-zz.

Pinned Loading

  1. CyberChefCyberChefPublic

    Forked from gchq/CyberChef

    This fork extends CyberChef with a focused set of payment cryptography operations intended for engineering, debugging, and interoperability work in regulated payment environments.

    JavaScript 2

  2. aws-payment-cryptography-hsm-proxyaws-payment-cryptography-hsm-proxyPublic

    Rust TCP proxy: translate Thales payShield 10K and Futurex Excrypt wire commands to AWS Payment Cryptography API calls, without changing the application.

    Rust 2

  3. aws-payment-cryptography-mcpaws-payment-cryptography-mcpPublic

    MCP server for AWS Payment Cryptography — key lifecycle, HSM migration analysis, and PCI-aware cryptographic operations. Works with Claude Code, Codex CLI, and any MCP-compatible client.

    Python 1

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
View J8k3's full-sized avatar
💭
Building things. Writing about it at jacobmarks.com.
💭
Building things. Writing about it at jacobmarks.com.

Block or report J8k3

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
J8k3/README.md

Jacob Marks

Senior Engineering Leader | Payment Cryptography | Distributed Systems | ex-AWS

I build and scale security-critical, regulated infrastructure where correctness, compliance, and availability are non-negotiable. Most recently I led the architecture and launch of AWS Payment Cryptography, a globally deployed, hardware-backed cryptographic service, taking it from ambiguous customer input to production under strict PCI and regulatory constraints.

I operate at the boundary between deep technical design and durable execution: defining systems, authoring threat models, governing hardware and software designs, and building the operational practices that hold up over time. I stay hands-on in critical paths and set technical direction that scales beyond my direct involvement.

Currently targeting Director of Engineering, VP Engineering, or senior IC roles in fintech, payments, and security-critical infrastructure.

📄 Blog & Website · 💼 LinkedIn


🔧 Active Projects

CyberChef Payments

J8k3/CyberChef · J8k3/CyberChef-Payments, AI-assisted development

A fork of GCHQ's CyberChef extended with payment cryptography tooling for engineering, debugging, interoperability testing, and standards exploration. If you've done this work in payments you know the time it takes to test schemes and data structures without a live HSM. That's the gap this fills.

J8k3/CyberChef — the implementation fork. Operations cover EMV (ARQC/ARPC, issuer scripts, MAC), PIN (blocks, DUKPT TDES/AES, IBM 3624, Visa PVV), MAC, card validation, key management (TR-31, TR-34, ECDH, KCV), and HSM command parsing (Thales payShield, Futurex). All operations are explicit, inspectable, and composable. Fully client-side, nothing leaves your browser.

J8k3/CyberChef-Payments — workflow catalog with recipe links, screenshots, chaining patterns, and validation status across all operations.

🌐 Live demo: cyberchef.jacobmarks.com

AWS Payment Cryptography HSM Proxy

J8k3/aws-payment-cryptography-hsm-proxy, AI-assisted development

A local proxy that speaks the wire protocols of physical payment HSMs (Thales payShield, Futurex Excrypt) and maps them onto AWS Payment Cryptography, so existing payment applications, test harnesses, and integrations keep working without rewriting against the AWS SDK. The goal is portability rather than one-way migration: your application talks to a stable HSM-style interface while the platform behind it can change, creating interoperability across payment HSM platforms instead of locking you to any single one.

AWS Payment Cryptography MCP

J8k3/aws-payment-cryptography-mcp, AI-assisted development

A Model Context Protocol server for AWS Payment Cryptography. Companion to the HSM proxy. Exposes APC operations as MCP tools so LLM-driven agents and assistants can perform structured payment cryptography work with proper boundaries.


🏗️ Engineering Background

AWS Payment Cryptography (2021–2026)

Led the definition, architecture, and launch of a globally deployed, hardware-backed cryptography-as-a-service platform, a first of its kind in the cloud.

  • Authored the foundational threat model and security posture from early customer input through launch and steady-state
  • Defined and governed control-plane, data-plane, and hardware designs, maintaining system coherence through technical review
  • Established operational and observability practices focused on customer impact and failure modes
  • Introduced daily HSM fleet health evaluation, reducing unsellable capacity from ~10% toward ~5%
  • Established hardware-backed design patterns later reused across related cryptographic services

EC2 Core Platform (2018–2021)

Owned core EC2 platform services and led architectural improvements at massive scale.

  • Led architectural separation of telemetry and billing systems supporting hundreds of petabytes of customer data
  • Owned platform-level reliability and cost tradeoffs across core EC2 infrastructure during periods of rapid scale

Defense & National Security (Booz Allen Hamilton, 2008–2016)

Progressed from hands-on engineer into technical and program leadership on systems operating under security and compliance constraints.


🛠️ Technical Depth

  • Languages: C# / .NET (primary), Javascript, Python, Rust
  • Domains: Payment cryptography, HSM/PCI compliance, distributed systems, key management, cloud infrastructure
  • Security: Threat modeling, PCI-DSS, NIST/DoD ATO, hardware security modules
  • Leadership: Multi-team engineering orgs, technical direction, engineering management

📁 Other Projects

  • aws-ms-deploy-assistant, AWS Labs project (contributions under legacy account @J8K3-zz)
  • LightningPDF, fast-loading PDF viewer with merge, rotate, and reorder features; built for speed when reviewing large document volumes (C#)
  • document-sorter, PDF document classifier that automatically organizes scanned documents into folders based on keyword matching rules (C#)
  • awssescredgen, CLI tooling for AWS SES credential generation (C#)
  • speventreceiverman, utility for SharePoint event receiver management (C#)

Note on GitHub accounts: Due to a legacy account recovery issue, my original profile was renamed by GitHub. Current active account: @J8k3. Historical contributions: @J8K3-zz.

Pinned Loading

  1. CyberChefCyberChefPublic

    Forked from gchq/CyberChef

    This fork extends CyberChef with a focused set of payment cryptography operations intended for engineering, debugging, and interoperability work in regulated payment environments.

    JavaScript 2

  2. aws-payment-cryptography-hsm-proxyaws-payment-cryptography-hsm-proxyPublic

    Rust TCP proxy: translate Thales payShield 10K and Futurex Excrypt wire commands to AWS Payment Cryptography API calls, without changing the application.

    Rust 2

  3. aws-payment-cryptography-mcpaws-payment-cryptography-mcpPublic

    MCP server for AWS Payment Cryptography — key lifecycle, HSM migration analysis, and PCI-aware cryptographic operations. Works with Claude Code, Codex CLI, and any MCP-compatible client.

    Python 1

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
View J8k3's full-sized avatar
💭
Building things. Writing about it at jacobmarks.com.
💭
Building things. Writing about it at jacobmarks.com.

Block or report J8k3

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
J8k3/README.md

Jacob Marks

Senior Engineering Leader | Payment Cryptography | Distributed Systems | ex-AWS

I build and scale security-critical, regulated infrastructure where correctness, compliance, and availability are non-negotiable. Most recently I led the architecture and launch of AWS Payment Cryptography, a globally deployed, hardware-backed cryptographic service, taking it from ambiguous customer input to production under strict PCI and regulatory constraints.

I operate at the boundary between deep technical design and durable execution: defining systems, authoring threat models, governing hardware and software designs, and building the operational practices that hold up over time. I stay hands-on in critical paths and set technical direction that scales beyond my direct involvement.

Currently targeting Director of Engineering, VP Engineering, or senior IC roles in fintech, payments, and security-critical infrastructure.

📄 Blog & Website · 💼 LinkedIn


🔧 Active Projects

CyberChef Payments

J8k3/CyberChef · J8k3/CyberChef-Payments, AI-assisted development

A fork of GCHQ's CyberChef extended with payment cryptography tooling for engineering, debugging, interoperability testing, and standards exploration. If you've done this work in payments you know the time it takes to test schemes and data structures without a live HSM. That's the gap this fills.

J8k3/CyberChef — the implementation fork. Operations cover EMV (ARQC/ARPC, issuer scripts, MAC), PIN (blocks, DUKPT TDES/AES, IBM 3624, Visa PVV), MAC, card validation, key management (TR-31, TR-34, ECDH, KCV), and HSM command parsing (Thales payShield, Futurex). All operations are explicit, inspectable, and composable. Fully client-side, nothing leaves your browser.

J8k3/CyberChef-Payments — workflow catalog with recipe links, screenshots, chaining patterns, and validation status across all operations.

🌐 Live demo: cyberchef.jacobmarks.com

AWS Payment Cryptography HSM Proxy

J8k3/aws-payment-cryptography-hsm-proxy, AI-assisted development

A local proxy that speaks the wire protocols of physical payment HSMs (Thales payShield, Futurex Excrypt) and maps them onto AWS Payment Cryptography, so existing payment applications, test harnesses, and integrations keep working without rewriting against the AWS SDK. The goal is portability rather than one-way migration: your application talks to a stable HSM-style interface while the platform behind it can change, creating interoperability across payment HSM platforms instead of locking you to any single one.

AWS Payment Cryptography MCP

J8k3/aws-payment-cryptography-mcp, AI-assisted development

A Model Context Protocol server for AWS Payment Cryptography. Companion to the HSM proxy. Exposes APC operations as MCP tools so LLM-driven agents and assistants can perform structured payment cryptography work with proper boundaries.


🏗️ Engineering Background

AWS Payment Cryptography (2021–2026)

Led the definition, architecture, and launch of a globally deployed, hardware-backed cryptography-as-a-service platform, a first of its kind in the cloud.

  • Authored the foundational threat model and security posture from early customer input through launch and steady-state
  • Defined and governed control-plane, data-plane, and hardware designs, maintaining system coherence through technical review
  • Established operational and observability practices focused on customer impact and failure modes
  • Introduced daily HSM fleet health evaluation, reducing unsellable capacity from ~10% toward ~5%
  • Established hardware-backed design patterns later reused across related cryptographic services

EC2 Core Platform (2018–2021)

Owned core EC2 platform services and led architectural improvements at massive scale.

  • Led architectural separation of telemetry and billing systems supporting hundreds of petabytes of customer data
  • Owned platform-level reliability and cost tradeoffs across core EC2 infrastructure during periods of rapid scale

Defense & National Security (Booz Allen Hamilton, 2008–2016)

Progressed from hands-on engineer into technical and program leadership on systems operating under security and compliance constraints.


🛠️ Technical Depth

  • Languages: C# / .NET (primary), Javascript, Python, Rust
  • Domains: Payment cryptography, HSM/PCI compliance, distributed systems, key management, cloud infrastructure
  • Security: Threat modeling, PCI-DSS, NIST/DoD ATO, hardware security modules
  • Leadership: Multi-team engineering orgs, technical direction, engineering management

📁 Other Projects

  • aws-ms-deploy-assistant, AWS Labs project (contributions under legacy account @J8K3-zz)
  • LightningPDF, fast-loading PDF viewer with merge, rotate, and reorder features; built for speed when reviewing large document volumes (C#)
  • document-sorter, PDF document classifier that automatically organizes scanned documents into folders based on keyword matching rules (C#)
  • awssescredgen, CLI tooling for AWS SES credential generation (C#)
  • speventreceiverman, utility for SharePoint event receiver management (C#)

Note on GitHub accounts: Due to a legacy account recovery issue, my original profile was renamed by GitHub. Current active account: @J8k3. Historical contributions: @J8K3-zz.

Pinned Loading

  1. CyberChefCyberChefPublic

    Forked from gchq/CyberChef

    This fork extends CyberChef with a focused set of payment cryptography operations intended for engineering, debugging, and interoperability work in regulated payment environments.

    JavaScript 2

  2. aws-payment-cryptography-hsm-proxyaws-payment-cryptography-hsm-proxyPublic

    Rust TCP proxy: translate Thales payShield 10K and Futurex Excrypt wire commands to AWS Payment Cryptography API calls, without changing the application.

    Rust 2

  3. aws-payment-cryptography-mcpaws-payment-cryptography-mcpPublic

    MCP server for AWS Payment Cryptography — key lifecycle, HSM migration analysis, and PCI-aware cryptographic operations. Works with Claude Code, Codex CLI, and any MCP-compatible client.

    Python 1

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
View J8k3's full-sized avatar
💭
Building things. Writing about it at jacobmarks.com.
💭
Building things. Writing about it at jacobmarks.com.

Block or report J8k3

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
J8k3/README.md

Jacob Marks

Senior Engineering Leader | Payment Cryptography | Distributed Systems | ex-AWS

I build and scale security-critical, regulated infrastructure where correctness, compliance, and availability are non-negotiable. Most recently I led the architecture and launch of AWS Payment Cryptography, a globally deployed, hardware-backed cryptographic service, taking it from ambiguous customer input to production under strict PCI and regulatory constraints.

I operate at the boundary between deep technical design and durable execution: defining systems, authoring threat models, governing hardware and software designs, and building the operational practices that hold up over time. I stay hands-on in critical paths and set technical direction that scales beyond my direct involvement.

Currently targeting Director of Engineering, VP Engineering, or senior IC roles in fintech, payments, and security-critical infrastructure.

📄 Blog & Website · 💼 LinkedIn


🔧 Active Projects

CyberChef Payments

J8k3/CyberChef · J8k3/CyberChef-Payments, AI-assisted development

A fork of GCHQ's CyberChef extended with payment cryptography tooling for engineering, debugging, interoperability testing, and standards exploration. If you've done this work in payments you know the time it takes to test schemes and data structures without a live HSM. That's the gap this fills.

J8k3/CyberChef — the implementation fork. Operations cover EMV (ARQC/ARPC, issuer scripts, MAC), PIN (blocks, DUKPT TDES/AES, IBM 3624, Visa PVV), MAC, card validation, key management (TR-31, TR-34, ECDH, KCV), and HSM command parsing (Thales payShield, Futurex). All operations are explicit, inspectable, and composable. Fully client-side, nothing leaves your browser.

J8k3/CyberChef-Payments — workflow catalog with recipe links, screenshots, chaining patterns, and validation status across all operations.

🌐 Live demo: cyberchef.jacobmarks.com

AWS Payment Cryptography HSM Proxy

J8k3/aws-payment-cryptography-hsm-proxy, AI-assisted development

A local proxy that speaks the wire protocols of physical payment HSMs (Thales payShield, Futurex Excrypt) and maps them onto AWS Payment Cryptography, so existing payment applications, test harnesses, and integrations keep working without rewriting against the AWS SDK. The goal is portability rather than one-way migration: your application talks to a stable HSM-style interface while the platform behind it can change, creating interoperability across payment HSM platforms instead of locking you to any single one.

AWS Payment Cryptography MCP

J8k3/aws-payment-cryptography-mcp, AI-assisted development

A Model Context Protocol server for AWS Payment Cryptography. Companion to the HSM proxy. Exposes APC operations as MCP tools so LLM-driven agents and assistants can perform structured payment cryptography work with proper boundaries.


🏗️ Engineering Background

AWS Payment Cryptography (2021–2026)

Led the definition, architecture, and launch of a globally deployed, hardware-backed cryptography-as-a-service platform, a first of its kind in the cloud.

  • Authored the foundational threat model and security posture from early customer input through launch and steady-state
  • Defined and governed control-plane, data-plane, and hardware designs, maintaining system coherence through technical review
  • Established operational and observability practices focused on customer impact and failure modes
  • Introduced daily HSM fleet health evaluation, reducing unsellable capacity from ~10% toward ~5%
  • Established hardware-backed design patterns later reused across related cryptographic services

EC2 Core Platform (2018–2021)

Owned core EC2 platform services and led architectural improvements at massive scale.

  • Led architectural separation of telemetry and billing systems supporting hundreds of petabytes of customer data
  • Owned platform-level reliability and cost tradeoffs across core EC2 infrastructure during periods of rapid scale

Defense & National Security (Booz Allen Hamilton, 2008–2016)

Progressed from hands-on engineer into technical and program leadership on systems operating under security and compliance constraints.


🛠️ Technical Depth

  • Languages: C# / .NET (primary), Javascript, Python, Rust
  • Domains: Payment cryptography, HSM/PCI compliance, distributed systems, key management, cloud infrastructure
  • Security: Threat modeling, PCI-DSS, NIST/DoD ATO, hardware security modules
  • Leadership: Multi-team engineering orgs, technical direction, engineering management

📁 Other Projects

  • aws-ms-deploy-assistant, AWS Labs project (contributions under legacy account @J8K3-zz)
  • LightningPDF, fast-loading PDF viewer with merge, rotate, and reorder features; built for speed when reviewing large document volumes (C#)
  • document-sorter, PDF document classifier that automatically organizes scanned documents into folders based on keyword matching rules (C#)
  • awssescredgen, CLI tooling for AWS SES credential generation (C#)
  • speventreceiverman, utility for SharePoint event receiver management (C#)

Note on GitHub accounts: Due to a legacy account recovery issue, my original profile was renamed by GitHub. Current active account: @J8k3. Historical contributions: @J8K3-zz.

Pinned Loading

  1. CyberChefCyberChefPublic

    Forked from gchq/CyberChef

    This fork extends CyberChef with a focused set of payment cryptography operations intended for engineering, debugging, and interoperability work in regulated payment environments.

    JavaScript 2

  2. aws-payment-cryptography-hsm-proxyaws-payment-cryptography-hsm-proxyPublic

    Rust TCP proxy: translate Thales payShield 10K and Futurex Excrypt wire commands to AWS Payment Cryptography API calls, without changing the application.

    Rust 2

  3. aws-payment-cryptography-mcpaws-payment-cryptography-mcpPublic

    MCP server for AWS Payment Cryptography — key lifecycle, HSM migration analysis, and PCI-aware cryptographic operations. Works with Claude Code, Codex CLI, and any MCP-compatible client.

    Python 1