I am a Principal Product Manager at Microsoft working at the intersection of cloud infrastructure, security, and trustworthy AI. My career has followed one recurring question: what does a system need to prove before people can safely trust it with something consequential?
That question has taken me from mobile payments and cryptographic services to secure multiparty computation, confidential cloud platforms, and the emerging security model for autonomous AI agents.
What I work on now
I lead product strategy for Confidential Containers on Azure Container Instances, helping organizations run sensitive container workloads with stronger isolation and a smaller trust boundary.
My work spans product direction, customer discovery, technical tradeoffs, roadmap decisions, and alignment across engineering, design, go-to-market, security, and partner teams.
Selected work
Confidential cloud platforms
- Lead product strategy for confidential container workloads on Azure.
- Translate enterprise security, privacy, and compliance requirements into platform capabilities.
- Connect customer needs, technical constraints, and go-to-market priorities across organizational boundaries.
Secure multiparty systems
At Royal Bank of Canada, I directed development of the Virtual Clean Room, a platform using Intel SGX and confidential computing to support secure collaboration across organizational trust boundaries. I also designed APIs for cryptographic services, key management, and token signing.
Mobile payments
I helped launch North America’s first host card emulation–based mobile wallet and worked on secure storage, tokenized transactions, behavioral biometrics, and multifactor authentication across banking and payment products.
Inventions
I am a named inventor on ten granted U.S. patents covering secure electronic transactions, credential tokenization, multiparty secure computing, and consumer-information protection.
Agent security
AI agents collapse the distance between a model’s output and a real-world action. My recent work explores the infrastructure required to keep that action trustworthy: workload identity, bounded delegation, capability-based permissions, hardware isolation, attestation, secret release, and auditability.
- Trust Is the Next Bottleneck
- AI Agents Have an Identity Crisis
- MCP Is a Capability System
- Hardening MCP Servers with Confidential Computing
- MCP + TEE reference implementation
Speaking
- OC3 2026: The Weakest Link in AI: Hardening MCP Servers with Confidential Computing
- Open Source Summit / Linux Foundation: Trust Is the Next Bottleneck: Why the Agentic Economy Needs Confidential Computing
- Azure confidential computing: Unlock the Power of Private Data and Build Smarter AI Models
Where I am heading
I am especially interested in products that make powerful AI systems safe to deploy in sensitive environments: agent infrastructure, identity and authorization, privacy-preserving AI, multi-cloud trust controls, secure tool use, and verifiable execution.