I build the defensive tooling analysts actually use, and I'm aiming it at federal cyber operations — taking cybercrime off the board.
Flagship — PolicyScout / ArmSky A GAMECHANGER-inspired semantic-search + cited-QA engine over DoD policy. Hybrid BM25 + TF-IDF retrieval with RRF fusion and MMR, a cross-encoder-shaped reranker that took citation precision from 0.94 → 1.00, a grounded-LLM composer wired for Azure OpenAI Gov, nDCG + citation-precision gates in CI, and an adversarial critique log on every release. Built against the CDAO analytic-tools ecosystem (GAMECHANGER, Advana, JATIC).
Also shipped
- RangeCheck — authorized network exposure assessment, CVSS-tagged findings
- ControlTrace — STIG-style baseline auditing mapped to NIST 800-53 & MITRE ATT&CK
- Tracer — threat-intel pipeline (Elasticsearch + Neo4j correlation)
- SkimmerSentinel, Tarpit, CivicPulse, LicenseLoop — and the portfolio itself, hand-built with serverless functions
Credentials — Cisco Certified in Cybersecurity · (ISC)² Candidate · Blue Team Junior Analyst · 18 Anthropic AI certificates
Working with — Python · FastAPI · scikit-learn · Docker · Cloudflare · Neo4j · Elasticsearch · the MITRE ATT&CK framework
How I work — every project ships with tests, an eval harness, and an honest self-critique. Assume it's broken until the tests prove otherwise.
Hudson Valley / NYC metro · federal cyber operations · sergio.w.rdz@gmail.com · sergrdz.pages.dev