EngSecLabs is Alex Smolen's home for writing about security engineering and for the open-source security tools he builds. It grew out of a security consulting practice; these days Alex works full-time elsewhere, so the site is mostly the blog and the projects.
Still open to the occasional interesting project or advisory engagement. If something here resonates, say hello.
# open-source security tools $ ls projects/ trailtool/ # cloudtrail for ai agents iam-agent-proxy/ # least-privilege for aws agents graphgrc/ # soc 2 compliance in github $ cat blog/latest.md # notes on security engineering, # leadership, and practice. $ _
CloudTrail for AI agents. Pre-aggregates events into entities — people, sessions, roles, services — so agents can reason over cloud activity without blowing the context window.
Credential isolation and least privilege for AWS agents. Issues proxy fake keys, re-signs each request with real credentials, and generates a least-privilege policy from observed behavior.
SOC 2 compliance in GitHub. Pre-written controls and policies in Markdown with semantic linking — your compliance docs in version control, queryable by AI, not locked in a SaaS platform.
I'm a security engineer with over a decade of experience building and breaking security-critical systems. I've worked across application security, cloud infrastructure, AI security, and compliance at technology startups and high-growth companies.
I write about security engineering on this blog and on alexsmolen.com. If you're working through a hard security problem, I'd like to hear about it.
I'm heads-down full-time these days, but I still enjoy hearing from people about their work — a security problem you're chewing on, one of the open-source tools, or the occasional interesting project. Email is the best way to reach me:
alex@engseclabs.comOr drop a note below and I'll get back to you.