Skip to content
View Pharns's full-sized avatar

Highlights

  • Pro

Block or report Pharns

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Pharns/README.md

Pharns Genece

Open to WorkRemoteClearanceRF/SDR

Security Architect & AI Agent Governance Researcher

I build the controls I document — cloud guardrails, endpoint hardening, evidence pipelines, and detection workflows that stand up in real operations and audits.

📧 career@pharns.com · 🌐 portfolio.pharns.com · 💼 LinkedIn

Architect of the AQ Score™ — the independent measurement standard for governed autonomous action.

USAF Veteran · USPTO Patent-Filed (named inventor) · NIST OLIR Cataloged (×3, Final) · 17 Active Certifications


Why I'm different

  • I implement controls, not just map them. Framework requirements become working configurations, monitoring logic, and documented evidence — not recommendations in a report.
  • I connect governance to operations. Design through implementation through audit-ready outputs — the documentation reflects what actually runs.
  • Unusual edge-domain depth. RF/UAS security (USPTO patent filings, TraceLock™), governed automation systems, and real operator experience across USAF, a venture-funded drone logistics startup, and active consulting.

What I Build

GIAP™ — Governed Intake and Analysis Platform

Production GRC automation platform — end-to-end intake workflow with n8n orchestration and CISO Assistant.

  • Stack: Client portal + n8n + Nextcloud + SuiteCRM + DocuSeal + CISO Assistant (100+ frameworks)
  • Impact: ~70% reduction in audit prep time; HMAC-authenticated webhooks; live demo running
  • Status: Production MVP — 9 workflows operational
  • View Project → · Try Live Demo →

TraceLock™ — Multi-Domain RF Threat Detection

Patent-pending RF surveillance detection across 6 wireless domains simultaneously with forensic-grade logging.

  • Codebase: 25 Python modules · 81 shell scripts · ~12,500 LOC
  • Domains: Wi-Fi · BLE · SDR · GPS · ADS-B · ISM
  • Status: WGU BSCSIA Capstone · Patent Pending
  • View Project →

AWS Cloud Control Pack

S3 default-deny · GuardDuty findings export · Scoped IAM mapped to CIS/NIST

Detection & IR Lab

Security Onion SIEM with TheHive/Cortex case management, custom detection rules, and IR playbooks.

  • Detection Content: Sigma-style rules · Alert tuning · False positive reduction
  • View Project →

SDOS — A Governed Execution Framework for Autonomous AI Agents

Runtime governance for autonomous AI agents — policy enforcement at the point of action, not after.

  • What it does: classifies each agent action by risk tier before it runs, and enforces policy at the point of action rather than after the fact
  • Governance: agent behavior is checked against policy before execution, not merely logged afterward
  • Memory: agent memory is governed under the same policy pipeline as agent actions
  • Audit: immutable, append-only decision log — not modifiable by governed agents
  • Status: Operational — subject of multiple USPTO provisional filings (first: 64/029,300); cataloged in the NIST OLIR program as three Final Informative References (Ref 220 / AI RMF 1.0, Ref 215 / CSF 2.0, Ref 217 / SP 800-53 Rev 5.2.0)
  • View Project →

dbt CTI Pipeline — Behavioral Analytics from Threat Feeds

Ingests live CTI feeds (abuse.ch URLhaus + ThreatFox) and transforms them into behavioral-analytics tables with dbt.

  • Stack: dbt Core · DuckDB · Python — staging → intermediate → mart models, tested and documented
  • Marts: IOC volume by threat family · daily volume vs. 7-day baseline (anomaly-ready) · cross-feed corroborated IOCs (multi-source correlation)
  • Verified: 6 models · 14 passing tests · full lineage DAG
  • View Project →

AgenticOS

Deterministic AI agent orchestration with explainable routing and audit-grade logging.

  • Codebase: 6,361 lines Python · 72 health checks · 4 provider integrations
  • View Project →

Results

MetricValue
Production infrastructure security7 years (USOG, 2017–2024)
Vulnerabilities remediated15,000+
PCI-DSS endpoint hardening<48 hours with full evidence pack
Framework implementationCIS v8 → NIST CSF → SOC 2 across regulated environments
Client compliance deliveredHIPAA · PCI-DSS · SOC 2 (healthcare, financial services, legal)
Active certifications17

AAM / Cyber-Physical Differentiation

Few practitioners combine these:

  • USPTO patent filings (named inventor) in UAV payload and delivery architectures
  • TraceLock™ — patent-pending 6-domain RF detection platform
  • FAA Part 107 certified · HAM/GMRS licensed
  • SDR/wireless expertise — RTL-SDR, HackRF, Kismet, spectrum analysis
  • USAF career veteran — mission-critical operations background
  • UAV engineering & operations leadership — 7 years hands-on across a drone logistics venture (payload/delivery architectures)

Technical Expertise

DomainSkills
GRC & FrameworksCIS Controls v8 · NIST CSF · PCI-DSS v4.0 · SOC 2 · ISO 27001 · HIPAA
Cloud SecurityAWS IAM · S3 · GuardDuty · CloudTrail · Policy-as-Code
Detection EngineeringSecurity Onion · TheHive/Cortex · Sigma · SIEM tuning · RF threat detection
AutomationPython · n8n · CISO Assistant · Evidence pipelines · Webhook security
RF/WirelessRTL-SDR · HackRF · Kismet · BLE · ADS-B · SDR signal analysis

Credentials

Active (17)

Security+ · CySA+ · PenTest+ · Network+ · A+ · Project+ · CSAP · CSIS · CIOS · ISC² SSCP · ISC² CC · ITIL 4 · LPI · CNSP (CompTIA) · CNVP (CompTIA) · CNSP (SecOps Group) · CNVP (SecOps Group)

Federal & Standards

NIST OLIR Program — 3 Final Informative References cataloged (AI RMF 1.0, CSF 2.0, SP 800-53 Rev 5.2.0)

Planned (2026)

AWS Cloud Practitioner · ISC² CCSP

Education

B.S. Cybersecurity & Information Assurance — Western Governors University, March 2026 Capstone: TraceLock™


Actively Seeking

CategoryDetails
Target RolesSecurity Architect · GRC Engineer · Cloud Security Engineer · Detection Engineer
AvailabilityAvailable now
Work StyleRemote-first · Async-ready · Distributed team experience
LocationUS-based · Remote US/EU/International welcome
EngagementW-2 · Contract · Consulting — 1099 available for international

Best fit for teams that need implementation, not just policy decks.


Connect

ChannelLink
Emailcareer@pharns.com
Portfolioportfolio.pharns.com
LinkedInlinkedin.com/in/pharns
CertificationsCredly

Security architect/operator who turns governance into implemented controls, telemetry, and evidence. US Citizen · USAF veteran · Open to remote roles worldwide.

Pinned Loading

  1. The-Five-Laws-of-AI-GovernanceThe-Five-Laws-of-AI-GovernancePublic

    The Five Laws of AI Governance also referred to as The 5 Laws of AI Governance, this document defines…

  2. tracelock-publictracelock-publicPublic

    Public-safe overview of TraceLock™ — patent-pending multi-domain RF threat detection platform (Wi-Fi/BLE/SDR/GPS/ADS-B). Detection engineering with Python automation and forensic-grade logging.

  3. detection-rulesdetection-rulesPublic

    Custom Sigma-style detection rules for SIEM platforms — DNS tunneling, HTTP anomalies, lateral movement, authentication attacks, and exfiltration. 12 rules across 5 categories.

  4. portfolioportfolioPublic

    Security engineering portfolio — GRC, cloud security, detection engineering, and RF/UAS security. Built with MkDocs Material.

    HTML 1

  5. dbt-cti-pipelinedbt-cti-pipelinePublic

    CTI behavioral-analytics pipeline — live abuse.ch feeds → dbt (staging→marts, tested, documented) on DuckDB. 6 models, 14 passing tests.

    Python

  6. sdos-publicsdos-publicPublic

    Runtime governance for autonomous AI agents — policy enforcement at the point of action