→ AI Security Architect · Agentic Systems · Easley, SC · Remote

25+ years building software.
Now I build and secure agentic AI systems.

I build agentic AI systems and I secure them. A decade running an AppSec program protecting 250+ enterprise applications — as one of two people. GWAPT-certified web application penetration tester, now pointing that same offensive mindset at a new attack surface.

Chris McNabb, AI Security Architect
→ What I Keep Building
900 22
Application-package-CVE questions collapsed to distinct vulnerability profiles
Days <3 hrs
DAST scan-to-ticket cycle, automated end to end
250+ 2
Enterprise applications secured, by a two-person team
→ What I Do

Three things I'm actually good at.

Architect, build, and ship agentic systems myself

LangGraph multi-agent pipelines, MCP servers, RAG, human-in-the-loop workflows. Not slideware. Running code, deployed, in use.

Break and secure AI systems

LLM and agentic-system security. Prompt injection, tool-use abuse, MCP server trust boundaries, agent authorization. The same offensive mindset, pointed at a new attack surface.

Run an AppSec program at scale

DAST, SAST, SCA, threat modeling, secure code review, and vulnerability management across 250+ apps with a two-person team. Automation and ruthless prioritization are what make that math work.

→ What I've Built

Real systems. Running code. That I built.

Two of these run against proprietary or personal data, so the repositories stay private — you get the architecture instead of the source. I'm happy to walk through any of it in person.

Live · Interactive prototype

Vexillum

An open-source vulnerability triage pipeline you can click through.

A vendor scans a thousand packages and sends a hundred reports a week. But a report isn't a decision — each one has to be resolved against every application consuming that package, so a hundred reports become roughly nine hundred questions. Those collapse to about twenty-two distinct CVEs, because every Java service pulls the same Spring and Jackson stack, so the expensive reasoning happens once per CVE instead of once per report. One rule underneath it: a model may return a proposal, but it may never write to the datastore. Deterministic code parses, resolves, and commits.

Synthetic data throughout — a design artifact for making an architecture arguable, not a system wired to live data.
ReactViteTailwind RechartsOpenVEXSBOM / SCA
DAST PIPELINE Scan intakeDAST findings Normalizededupe + cluster RAG enrichmentprior findings LLM triageseverity + risk Analyst gateinterrupt / resume RemediationServiceNow ticket Prompt-injection guardrails scanner output treated as untrusted input
Private · Architecture shown

Bastros

Full-stack DAST orchestration console.

Scanner findings are normalized and clustered, enriched against a vector store of prior findings and remediation guidance, then triaged by an LLM for severity and exploitability. Nothing reaches a ticket without passing an analyst gate — a LangGraph interrupt that suspends the run for human approval and resumes from checkpointed state. Scanner output is treated as untrusted input throughout, because a finding body is attacker-influenced text heading straight for a model's context window. This is the AppSec program I run, rebuilt as an agentic system.

LangGraphClaude APIRAG FastAPIReactHITL interrupts Prompt-injection guardrails
React Dashboard FastAPI Google OAuth PKCE Claude API Sonnet Scout graph job discovery Morning brief calendar + inbox Meeting prep research + recall SqliteSaver checkpointing interrupt / resume · durable state across runs
Private · Architecture shown

Chief of Staff Dashboard

Multi-graph LangGraph application for daily operations.

A scout graph, a morning brief graph, and a meeting prep graph coordinating behind a React front end and FastAPI back end, with Google OAuth (PKCE) for Gmail and Calendar scopes. Production patterns rather than a demo: real OAuth, real API integrations, secrets in macOS Keychain via direnv.

LangGraphFastAPIReact Google OAuth (PKCE)Claude API
This tool runs against my live calendar, inbox, and personal data, so the repository stays private. Architecture shown instead — happy to walk through it in person.
SIX DIMENSIONS Data access Tool permissions Auth model Supply chain Network egress Vendor trust Weighted scoring Escalation rules 4 triggers Approve Conditionalwith controls Rejectredesign Nine pipeline stages from intake request to production approval
Design artifact

MCP Intake & Risk Gate

A scoring model for evaluating MCP servers before they reach production.

Six weighted risk dimensions, four escalation rules, nine pipeline stages. Most organizations are about to connect agents to internal tools with no intake process at all. This is the governance layer — designed by someone who does the offensive testing, not by someone reading about it.

Threat modelingMCP Risk scoringAI governance
Also shipped: two production PWAs on Astro + Cloudflare + Supabase with row-level security and Google OAuth — including one migrated to Astro 7 and Workers in response to disclosed CVEs — plus a Claude Code skill that harvests a site with Firecrawl and rebuilds it.
→ Track Record

Where I've done it.

2023 — PRESENT

Founder & AI Systems Architect

Cat Scratch Media, LLC · chrismcnabb.ai
  • Founded and run an independent practice building automation for security and business operations — moving into AI and agentic systems in 2024.
  • Design and build multi-agent pipelines with LangGraph and the Claude API — fan-out/fan-in orchestration, durable checkpointing, and human-in-the-loop interrupts that pause execution for human approval.
  • Build and operate MCP servers and Claude Code skills, plus a six-dimension risk-scoring model for evaluating MCP servers before they reach production.
  • Red-team my own systems with PyRIT and Garak — targeting stored prompt injection, tool-use abuse, and agent authorization boundaries.
  • Ship and maintain production web applications on Astro, Cloudflare Workers, and Supabase with row-level security and Google OAuth (PKCE).
  • Design end-to-end workflow automation with n8n, Make.com, and GitHub Actions, orchestrating LLMs, APIs, and business systems into production pipelines.
  • Member, Anthropic Claude Partner Network.
2016 — 2026

Software Security Architect

American Fidelity · Oklahoma City, OK (Remote)
  • Architect and run the application security program protecting 250+ enterprise web applications and APIs — one of a two-person team.
  • Built a fully automated DAST process-management system integrated with the ServiceNow ticket lifecycle, cutting a multi-day manual process to under three hours.
  • Triage and drive remediation of thousands of vulnerabilities per year, partnering with development teams to embed security into delivery.
  • Write and review cybersecurity standards and policy supporting PCI DSS, HIPAA, and SOC 2 across the application portfolio.
  • Hands-on web application penetration testing with Burp Suite Professional, including custom extension development to extend coverage.
  • Own and deliver secure coding training for 150+ developers.
2014 — 2017 · CONCURRENT, PART-TIME

Senior Software Consultant

Onlife Health · Franklin, TN (Remote)
  • Designed and built a custom HIPAA-compliant health and wellness platform serving 500,000+ members.
2014 — 2017 · PART-TIME

Consultant / Senior Developer & Architect

CIC, Inc. · Cleveland, TN (Remote)
  • Full-stack custom software development in C# / .NET and SQL Server.
2000 — 2014

Earlier engineering roles

Senior Developer · Team Lead · Architect

Firma8, Cloudswell, Ticketsoft, GHN Online, and Intervoice — spanning open-source translation systems, cloud services, enterprise point-of-sale, healthcare claims processing, and IVR / speech recognition platforms.

→ Credentials

Paper that backs the work.

In Progress

CAISP — Certified AI Security Professional

Practical DevSecOps · OWASP LLM Top 10, MITRE ATLAS, AI threat modeling with STRIDE, AI supply chain security

In Progress

Claude Certified Architect — Foundations (CCA-F)

Anthropic · Agentic architecture, MCP, Claude Agent SDK, context management

Held since 2018

GWAPT

GIAC Web Application Penetration Tester

2026

ISC2 Certified in Cybersecurity (CC)

ISC2

Earned

Swimlane SOAR Certified

SCSU · SCSA · SCSD

Earned

Distinguished Toastmaster (DTM)

Toastmasters International · highest achievement in the program

Education

M.S., Cybersecurity & Information Assurance
Western Governors University · expected 2027

B.S., Electrical Engineering
New Mexico State University

Earlier career: Microsoft MCSD, MCAD, MCDBA, MCSE

Clearances

DoD Secret & DoE Q

Inactive — eligible for reinstatement

Member, Anthropic Claude Partner Network — certification registration runs through the Anthropic Partner Academy, which is tied to the Partner Network.

→ The Other Half

AI and security only work if people understand them.

I've spent 40 years teaching hard things in simple ways — and I've delivered secure coding training to more than 150 developers. Most security programs don't fail on tooling. They fail because nobody changed what developers actually do on a Tuesday afternoon. Changing that is a communication problem before it's a technical one. I'm a Distinguished Toastmaster, which is a fancy way of saying I've done the reps.

→ Get In Touch

Let's talk.

Happy to talk through AI automation, agentic security architecture, AppSec programs, or anything I've built here.