Leadership Profile
Security leader with 20+ years building and owning global security programs: GRC, custody risk, SecOps, and platform security across distributed teams in regulated, high-scale, and digital-asset environments.
At Chia Network, I established security and IT operations and own architecture for HSM-based multi-signature custody and signing authorization: transaction authorization, policy controls, delegated approvals, and enterprise key management for high-value treasury operations across three continents. I partner with engineering on threat modeling, attack-path analysis, and security architecture reviews as formal pre-production gates across all internal and external repositories.
I lead secure agentic adoption (~90% of employees): data classification, access models, human-in-the-loop controls, and SDLC guardrails that improved release velocity roughly 4x while limiting blast radius. I founded bug bounty and coordinated disclosure with automated triage marking 99.9% of thousands of daily submissions duplicate before analyst review.
Programs align to NIST CSF, ISO 27001, and SOC 2 Type II. I partner with legal, auditors, vendors, and law enforcement on compliance, third-party risk, and financial-crime mitigation.
Previously at T-Mobile, I led platform security architecture for 35,000 internal engineers and a 30-engineer team modernizing GitLab-driven CI/CD, secrets management, and DevSecOps at enterprise scale.
I specialize in architecting and scaling Secure-by-Design frameworks for financial services and decentralized ecosystems. My leadership is defined by procedural discipline, documentation, and zero-trust integrity across high-value assets.
Security is a team sport!
Security Program at a Glance
| Domain | Program Outcomes |
|---|---|
| GRC | SOC 2 Type II certified; ISO 27001 readiness; NIST CSF alignment; automated audit cycles reducing prep from six weeks to three |
| Custody & Treasury Risk | HSM-based multi-signature signing authorization; transaction policy controls and delegated approvals; $200M treasury protection; key-holder safety program across three continents |
| Signing & Key Management | Enterprise key lifecycle; secure signing workflows; secrets management; privileged access; PKI-adjacent services |
| Global Operations | Security practice across 10 countries and 4 continents; US, EMEA, and APAC footprint with 99.9999% critical-service uptime |
| AppSec & Supply Chain | Open-source security at investment-bank attacker scale; supply chain hardening across all internal and external repositories; architecture review before production; bug bounty with automated triage (99.9% of thousands of daily submissions marked duplicate) |
| Agentic & AI Security | ~90% employee adoption; data classification; human-in-the-loop controls; control-by-design for AI-assisted development; ~4x release velocity |
| Detection & Response | Daily SIEM triage and remediation; incident response and threat modeling; residual risk assessment; pen test coordination; blameless post-mortem culture |
| DevSecOps at Scale | T-Mobile GitLab platform serving 35,000 engineers; 100,000+ daily pipeline activities; machine/service identities and pipeline secrets; enterprise DevSecOps transformation |
Current Focus
Vice President of Security at Chia Network
Dec 2022 to PresentChia blockchain is a massive open source project, so the security model is very unique. We face the problems and attacker scale of a major investment bank while providing all of our code for public review and attack.
As a hands-on executive leader, I own security architecture, GRC, operational security, employee safety, and global logistics for a distributed organization. I focus on resilience, compliance, and repeatability across custody, infrastructure, and enterprise risk.
- Architected and deployed HSM-based multi-signature custody and signing authorization: transaction authorization, policy controls, delegated approvals, and secure signing workflows for high-value treasury operations across three continents
- Established threat modeling, attack-path analysis, and security architecture reviews as formal pre-production checkpoints across all internal and external repositories
- Founded coordinated disclosure and bug bounty; automated triage marking 99.9% of thousands of daily submissions duplicate before analyst review
- Led secure agentic adoption (~90% of employees): data classification, access models, human-in-the-loop controls, and SDLC guardrails; ~4x release velocity with bounded blast radius
- Designed, built, and deployed HSM-based crypto spend management across three continents, cutting treasury spend resolution time by three days
- Created and implemented real-time safety and asset protection for key holders to a treasury worth $200 million
- Shortened SOC control audit prep from six weeks to three, passing our second SOC II Type 2 certification in Q2 2026
- Operated a globe-spanning security practice (10 countries, 4 continents) spanning crypto asset spends, key employee safety, internal security, and GRC
- Selected and implemented specialized logistics and colocation vendors across the US, Europe, and Southeast Asia, providing 99.9999% uptime for critical services
- Triaged and remediated dozens of SIEM events daily
- Built and led a lean global security engineering function that punches above its weight across GRC, SecOps, custody, and infrastructure
HSM Custody & Signing Authorization
The HSM-based authorization system I architected at Chia secures high-value treasury and settlement operations:
- Signing & authorization: Multi-signature workflows, transaction authorization, policy controls, and delegated approvals
- Key management: Enterprise key lifecycle, HSM-backed signing, secrets management, and privileged access
- Blast radius: Policy-bound controls limiting who can sign, what can move, and under what conditions
- Assurance: Threat modeling, security architecture review, and control-by-design delivery in regulated contexts
Thought Leadership & Blogs
Published on institutional custody, signing authorization, AI-assisted vulnerability management, and audit readiness.
Offensive & AI Security
Chia 2.7.1 is Out, Upgrade Now
The next step in our spring security push: post-mortems for 2.6.x and 2.7.0, plus fixes found after 2.7.0 shipped.
Read on Chia BlogSecurity Patches Q&A
Community Q&A on the 2.6.x / 2.7.x security releases and what we learned from AI-assisted bounty triage at scale.
Watch on YouTubeThe AI Siege: Combatting the LLM Attacker
A technical framework for AI-enabled threats; automated triage of thousands of daily bug bounty submissions with 99.9% marked duplicate before analyst review.
Read on Chia BlogWallet, Custody & Platform Security
Part 1: Wrench-Resistant by Design
Institutional custody and multi-signature design for real-world safety, not just cryptographic elegance.
View SeriesPart 2: Account model just isn't good enough
Why traditional account-based custody models fall short for high-value assets, and what a coin-set approach enables instead.
Read MorePart 3: What does all this mean?
Delegated authority and wrench-resistant design for operators, key holders, and the ecosystem.
Read MoreSOC 2 Type II Certification and Our Commitment to Security and Auditability
How Chia achieved SOC 2 Type II certification and what it signals about our commitment to security, auditability, and enterprise readiness.
Read MoreVideo: Global ASIC Rollout
Technical walkthrough of the global expansion of the Timelord network and ASIC hardware security.
Watch on YouTubeCareer Highlights
Head of Platform and Security at Chia Network
Oct 2020 to Dec 2022Joined Chia as head of Platform and Security during rapid growth, taking operations, DevOps, platform, and security responsibilities from the CEO. Sole ops/security engineer for roughly a year before hiring and growing the team to 14 engineers through public blockchain launch.
- Architected greenfield GCP/AWS platform security: IAM, network segmentation, secrets management, and hardened CI/CD from bare accounts to production
- Built security operations and IT infrastructure from employee #24 to 100, establishing the foundation for today's global security program
- Prepared the company for pre-IPO audits: SOC 2, ISO 27001, blameless post-mortem culture (Chia Network post-mortem repo)
- Hardened supply chain and delivery pipelines; mitigated 100+ security incidents daily across a massive open-source codebase
- Implemented incident response and threat modeling; 99.9999% uptime for critical services
- Instituted end-user security and tooling standards across all internal and external repositories
Principal Architect, Continuous Delivery Platform at T-Mobile
Jun 2019 to Oct 2020Principal Architect on the Continuous Delivery Platform team, servicing 35,000 internal engineers. Led a 30-engineer team shifting enterprise-wide DevOps pipelines, secrets management, and access control toward modern automated standards.
Designed and implemented a GitOps-driven CI/CD pipeline for T-Mobile's cloud-based platform, handling 100,000+ pull requests, merge requests, and engineer activities daily.
Secured the CI/CD pipeline and integrated security into all phases of the development lifecycle; addressed 1,500+ unique incidents daily while driving DevSecOps adoption across engineering teams.
Operationalized GitLab for enterprise-scale software delivery, reducing mean time to delivery across software projects by three weeks on average.
Governed machine/service identities and pipeline secrets; embedded security architecture into agile delivery for 35,000 engineers.
Side Projects
Selective advisory and founder work alongside my primary security leadership role.
Bastion Cyber Security
2023 to PresentArchitecture review, threat modeling, penetration testing coordination, and incident remediation for medium to large businesses.
Aetherguard
2025 to PresentSoftware-based signals intelligence for remote work, crypto asset holders, and high net worth individuals.
Vericreate
2026 to PresentProtect the Human Element in an Agentic Future. Cryptographically-backed proof of human contribution for students, educators, and academic integrity programs, as well as artists, coders, and designers.
What Colleagues Say
Colleagues from my enterprise platform security leadership at T-Mobile.
"Justin's approach to technology is rooted by his passion to always do what's right for his customers. Technology landscapes can be confusing and chaotic, but are ripe for Justin's ability to break down the concepts in simple terms and ensure there is continued progress. Justin is an asset for any team looking to build for the future."
"Justin was a huge part of an important cultural and technical shifts within T-Mobile that brought the T-Mobile 'customer first' attitude to our internal collaborations. Justin and team worked tirelessly to advocate for, overhaul, and automate stale business processes that were holding us back. As a result, we were able to move FAST to adopt and succeed with the Continuous Delivery Platform. My team has since enjoyed faster throughput, greater stability, and improved resiliency as a direct result of Justin's efforts."
"There are some people you work with where you're able to go 'oh so-and-so is taking care of that now' and you can just stop worrying about it getting done right. Justin is one of those people. Justin was a huge huge part of operationalizing GitLab for all of T-Mobile. I watched him shepherd a company that 'wasn't sure about this whole SaaS thing' into being comfortable leveraging a modern Git forge to deliver production software, and he did it in a way that kept internal developers, as the primary internal customer and sole source of value in a technology company, at the center, which was not by any means always easy to do."
"I had the privilege of working with Justin on a large job. Things were going sideways due to various factors, as things sometimes do. Justin stepped up; and through his can-do attitude, excellent architect skills, strong engineering understanding, and insightful leadership kept the situation from spiraling out of control. He utilized clear communication channels and frequent communications to keep teams informed of progress and next steps, reducing the stress of all involved. Justin has been added to the small list of people I trust. I would 110% work with Justin again given the chance."
"Justin is a top-notch Engineer that can easily become an invaluable 'Swiss Army Knife' for any team. He picks up new technologies quickly, adapts to situations with ease, and is a downright pleasure to work with. He has a 'can-do' attitude and I've witnessed him wield that attitude to conquer some massive problems. I highly recommend Justin and think he would be a great addition to any team."
Open to conversations about HSM custody and signing security architecture, digital-asset platform security, GRC program design, and security engineering leadership.
Get in touch