I am a Principal Product Manager at Microsoft working at the intersection of cloud infrastructure, security, and trustworthy AI. My career has followed one recurring question: what does a system need to prove before people can safely trust it with something consequential?

That question has taken me from mobile payments and cryptographic services to secure multiparty computation, confidential cloud platforms, and the emerging security model for autonomous AI agents.

What I work on now

I lead product strategy for Confidential Containers on Azure Container Instances, helping organizations run sensitive container workloads with stronger isolation and a smaller trust boundary.

My work spans product direction, customer discovery, technical tradeoffs, roadmap decisions, and alignment across engineering, design, go-to-market, security, and partner teams.

Selected work

Confidential cloud platforms

  • Lead product strategy for confidential container workloads on Azure.
  • Translate enterprise security, privacy, and compliance requirements into platform capabilities.
  • Connect customer needs, technical constraints, and go-to-market priorities across organizational boundaries.

Secure multiparty systems

At Royal Bank of Canada, I directed development of the Virtual Clean Room, a platform using Intel SGX and confidential computing to support secure collaboration across organizational trust boundaries. I also designed APIs for cryptographic services, key management, and token signing.

Mobile payments

I helped launch North America’s first host card emulation–based mobile wallet and worked on secure storage, tokenized transactions, behavioral biometrics, and multifactor authentication across banking and payment products.

Inventions

I am a named inventor on ten granted U.S. patents covering secure electronic transactions, credential tokenization, multiparty secure computing, and consumer-information protection.

Agent security

AI agents collapse the distance between a model’s output and a real-world action. My recent work explores the infrastructure required to keep that action trustworthy: workload identity, bounded delegation, capability-based permissions, hardware isolation, attestation, secret release, and auditability.

Speaking

Where I am heading

I am especially interested in products that make powerful AI systems safe to deploy in sensitive environments: agent infrastructure, identity and authorization, privacy-preserving AI, multi-cloud trust controls, secure tool use, and verifiable execution.

View my résumé or start a conversation.