I work at the intersection of governance, cybersecurity, human behavior, and AI-enabled systems. My focus is understanding how controls hold up or get bypassed across real organizational contexts.
I study Cyber Defense at UNDEF and Social Psychology at Instituto AMVA, combining technical security, governance, and behavioral analysis.
I build practical tools, assessments, and case studies around GRC, Human Risk, cybersecurity, and AI Security.
Governance, risk & analysis
| Work | What it is |
|---|---|
| Uber 2022 breach analysis | Post-incident analysis of MFA fatigue, social engineering, and hardcoded credentials, mapped to NIST CSF 2.0 and ISO/IEC 27001. |
| Auditing my own tool | Self-audit of web-vuln-control-mapping: four real findings across API input handling, security headers, dependencies, and an unpopulated control mapping. |
| OpenAI × Hugging Face 2026 case study | AI supply-chain and governance analysis. Published on sggaray.com. |
| Shadow AI Exposure Self-Assessment | Questionnaire-based exposure assessment for unsanctioned AI use. Published on sggaray.com. |
Technical
| Repository | What it is |
|---|---|
| web-vuln-control-mapping | Reference mapping common web vulnerabilities to risk, governance controls, and frameworks (OWASP, NIST, ISO/IEC 27001). Live |
| ParlAR | System-level offline voice dictation for Linux, Spanish first (faster-whisper + VAD). |
| GuionAR | Teleprompter overlay for Linux, voice-driven scrolling, socket integration with ParlAR (PyQt6). |
| Notita | Personal note-taking tool. Work in progress. |
Competitions
| Event | Date | Evidence |
|---|---|---|
| Cisco Americas Cyber Games 2026 | Jun 2026 | Writeups · full clear, 37/37 flags, 0 hints |
| CRDF CE3 / SANS BootUp CTF 2026 | Jul 2026 | Writeups · 38/47 challenges |

