I develop and deploy SaaS applications — data modeling through production infrastructure.
By day I do security engineering. That means alert triage, account-takeover investigations, and analyzing anomalous activity across an MSP-adjacent stack — ConnectWise, IT Glue, Wazuh. A lot of the job is reconstructing a sign-in timeline and deciding whether a risky login is a real compromise or a salesperson on hotel wifi. I'm working toward the ISC2 CISSP, with the exam booked for August 2026.
I got here the long way: a county sheriff's office, cable installation, a hospital service desk, a NOC watching 25,000 route miles of fiber, network engineering, threat intelligence, DevOps in a HIPAA shop, a SOC, and a year owning the security program for a city of 100,000 — water treatment, wastewater, police, fire, emergency operations. Fourteen years in IT, eight of them in security. I also spent a stretch locating underground utilities, which is its own education in what happens when nobody knows where the infrastructure is. The useful part of that route is that every layer I'm now responsible for defending, I've operated. When I ask an infrastructure team to change something, I know what I'm asking of them.
This blog is where that work gets written down: the home lab I test things in, the security engineering I do daily, and the SaaS work as it happens. No listicles, no "10 tips to secure your network." When I write something up it's because I hit a specific problem in a specific environment and the trade-offs were worth documenting — what I chose, what it cost, and what I'd do differently.
Reach me
- email hi@scottslab.io
- x @scottslabio
- github github.com/schlangens