Enterprise Cybersecurity & Applied Research

An engineering and technical research publication by Joshua A. Wortz, CISSP โ€” exploring Zero Trust cloud architectures, shift-left DevSecOps, active blue-team defense, and hands-on AI security.

Direct Collaboration & Engagements

“Partnering with colleges, conference organizers, and enterprise security leaders on accessible curriculum design, technical talks & panels, and defensive architecture advisory.”

Services & Engagements

Commercial Advisory, Instruction & Speaking

Direct collaboration for enterprise security teams, academic institutions, and industry events.

Verified Practice Senior Security Engineer at Eisenhower Health • ex-AWS • NCyTE National Faculty Fellow • CISSP
Enterprise & Cloud

Security & Zero Trust Advisory

Practical Zero Trust gap analysis, AWS/Azure security posture optimization, and least-privilege boundary design.

Engagement: 1โ€“4 week sprints, architecture reviews, or advisory retainers
  • โœ“ Detection Engineering: Custom Sentinel KQL analytic rules & automated playbooks
  • โœ“ Regulated Compliance: HIPAA/HITECH, NIST CSF & SP 800-53 audit readiness
  • โœ“ Cloud Posture: Least-privilege identity & multi-account trust validation
Hands-On Instruction

AI & SecOps Masterclasses

Live, high-engagement red/blue team workshops running entirely on zero-cost, containerized Docker sandboxes.

Engagement: Half-day or full-day hands-on labs (up to 25 seats, zero cloud cost)
  • โœ“ Securing Agentic AI & LLMs: Prompt injection defense, MCP & OPA gateways
  • โœ“ Modern Threat Hunting: Hands-on detection & incident triage in Microsoft Sentinel
  • โœ“ Zero Cloud Bills: Runs locally on standard 8GB laptops with Docker Desktop
Conferences & Classrooms

Technical Talks & Panels

Engaging, accessible technical talks delivering actionable insights on emerging threats, Zero Trust, and AI defense.

Engagement: 45โ€“60 min technical talk or panel + Q&A (virtual or on-site)
  • โœ“ Invited Talk / Briefing: The Next Threat Surface: Securing Model Context Protocol & AI Agents
  • โœ“ Technical Briefing: Demystifying Zero Trust for Real-World Infrastructure
  • โœ“ Academic Colloquia: MITRE ATT&CK breakdowns & live attack-chain forensics
Higher Ed & Pedagogy

UDL Curriculum & Lab Design

Designing barrier-free, multimodal cybersecurity and AI coursework tailored for neurodivergent and non-traditional learners.

Engagement: Turnkey course packages, OER lab engineering, or faculty training
  • โœ“ UDL Alignment: Multimodal visual topologies, structured rubrics & tactile labs
  • โœ“ OER Lab Engineering: Turnkey, zero-cost Linux & Docker courseware packages
  • โœ“ Faculty Training: Mentoring educators on integrating AI defense into curricula
Navigation Guide

Start Here: Targeted Pathways

Select your role or objective to discover curated blueprints, curricula, and defensive tools.

Executive & CISO

Enterprise Leaders & CISOs

Zero Trust blueprints, NIST SP 800-207 architectures, and executive risk governance frameworks designed for healthcare, cloud systems, and highly regulated industries.

NIST SP 800-207 SABSA Framework Healthcare Compliance CISO Roadmaps
Educators & Students

Educators & Students

Universal Design for Learning (UDL) aligned AI security curriculum, zero-cost Docker and Ollama defense labs, and open teaching materials from NCyTE workshops.

UDL Pedagogy Zero-Cost Labs Docker & Ollama NCyTE Workshops
AppSec & Blue Team

Security Engineers & Builders

Production-grade AppSec toolkits (StateHunter & AuditGuard), Microsoft Sentinel KQL query packs, and shift-left CI/CD automated security quality gates.

StateHunter & AuditGuard Sentinel KQL Packs CI/CD Quality Gates Safe Harbor SOW
Featured Spotlight

Flagship Research & Tooling

Spotlight on peer-reviewed enterprise architecture blueprints and open-source defensive software.

Flagship Academic Blueprint
Healthcare & Zero Trust

Enterprise Healthcare Security Architecture

Acuity Health Blueprint & Capstone Hotwash Synthesis

The definitive synthesis uniting enterprise Zero Trust architecture, DevSecOps pipelines, active defense deception, digital forensics, and executive governance into a production-ready healthcare reference blueprint.

Author: Joshua A. Wortz, CISSP
Standards: NIST SP 800-207 • SABSA • ISO 27001
Permanent DOI: 10.5281/zenodo.22287696
Flagship Open-Source Suite
AppSec & Recon

Application Security Suite

StateHunter (DevTools SPA Recon) + AuditGuard (Safe Harbor)

A two-stage offensive reconnaissance and defensive verification pipeline pairing browser DevTools runtime inspection with terminal mathematical boundary enforcement and Disclose.io Safe Harbor proof-of-adherence certification.

Architecture: Chrome MV3 + Python 3 CLI
Capabilities: SPA Route De-obfuscation • IDOR Prober
Compliance: FIRST CVSS v3.1 • Safe Harbor SOW

Core Publication Tracks

๐Ÿ“„

Research Papers & Blueprints

63 Blueprints, Frameworks & Technical Briefs

๐Ÿ›ก๏ธ

Acuity Health Security Architecture

Active Series โ€” 8 Parts

๐Ÿค–

Hands-On AI Security

Active Series โ€” 4 Parts

๐Ÿค–

NCyTE Fellowship

Completed Track โ€” 2 Parts

๐Ÿ› ๏ธ

Open Source & Security Tools

9 Production Tools: AuditGuard, StateHunter, Sentinel & AI

๐Ÿ‘ค

About & Philosophy

Enterprise Career, NCyTE Fellowship & Pedagogy

Latest Publications

Recent articles, research papers, and webinars
View All Articles →

Working Backwards from Error Logs: Reverse Engineering the Tableau-to-Fabric OAuth Breakdown

๐Ÿ›‘ The Crime Scene: A Misleading Desktop Failure When modern lakehouse architectures meet desktop analytics clients, authentication breakdowns rarely announce their true root cause. Instead, engineers are handed generic hex codes and deceptive UI prompts. During an enterprise deployment of Microsoft Fabric Warehouse, data analysts attempted to connect Tableau Desktop (2024.2.0) to the Fabric SQL/TDS endpoint (*.datawarehouse.fabric.microsoft.com) using the native Azure SQL Database connector and Microsoft Entra ID modern authentication. ...

October 2, 2026 ยท 9 min ยท 1767 words ยท Joshua Wortz

Hands-On AI Security: Policy-as-Code with Open Policy Agent and Rego

How to move beyond static regex filters by using Open Policy Agent (OPA) and Rego to enforce declarative, explainable security policies on AI prompts.

October 1, 2026 ยท 3 min ยท 495 words ยท Joshua Wortz

Acuity Health: Part 4 โ€” CI/CD Quality Gates & ISO 27001 Risk

Implement automated SAST, SCA, and DAST pipeline quality gates and operationalize the 10-step ISO 27001:2013 risk assessment methodology for cloud architectures.

September 29, 2026 ยท 7 min ยท 1317 words ยท Joshua Wortz

Hands-On AI Security: Blue Teaming and Building the Security Gateway

How to decouple AI defense from the model by building a Python Flask security proxy with hot-reloading ingress filters and egress data masking.

September 24, 2026 ยท 3 min ยท 564 words ยท Joshua Wortz

Acuity Health: Part 3 โ€” STRIDE Threat Modeling & BOLA Elimination

Integrate mini-STRIDE threat modeling into Agile sprint planning and implement bulletproof data-layer context checks against OWASP API1: BOLA.

September 22, 2026 ยท 6 min ยท 1256 words ยท Joshua Wortz

Modernizing the Academic Knowledge Graph: Canvas Sync Bridge v0.4.0, Hybrid Ingestion, and Official Obsidian Compliance

๐ŸŽ“ The Academic Knowledge Management Dilemma Modern higher education and enterprise training institutions rely almost universally on Learning Management Systems (LMS) like Instructure Canvas to distribute course syllabi, lecture modules, assignments, student discussions, and grading rubrics. Yet for technical students, researchers, and security practitioners who build their intellectual workflows inside personal knowledge management (PKM) systems like Obsidian, Canvas represents an isolated, walled-off data silo: Ephemerality & Term Expiration: Once an academic semester concludes, student access to Canvas courses is routinely archived or revoked. Syllabi, instructor annotations, curated reading lists, and assignment rubrics vanish behind institutional access gates. Disconnected Knowledge Graphs: Course notes authored in Obsidian remain disconnected from source materials, grading criteria, and module pacing guides living inside the web browser. Administrative Token Gating: Canvas exposes an extensive REST API, but institutional administrators frequently disable personal access tokens (Account > Settings > + New Access Token) for student roles due to enterprise compliance policies. Third-Party Cloud Aggregation Risks: Traditional third-party scrapers and web integrations require routing student session credentials, course documents, and peer discussions through external SaaS servers. For students handling proprietary lab code or education records governed by FERPA and GDPR, third-party cloud aggregation is an unacceptable privacy compromise. Third-Party Cloud Scraper (High Risk): [Canvas LMS] ----(Credentials/Course Data)----> [Cloud Relay / SaaS] ----> [Obsidian Vault] โ–ฒ โ””โ”€โ”€ Attack Surface & Data Leakage Risk Canvas Sync Bridge v0.4.0 (Hybrid Local-First Architecture): [Canvas LMS REST API] โ•โ•โ•โ•(Direct Token / requestUrl)โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•— โ–ผ [Canvas LMS Web Tab] โ•โ•โ•โ•(Session Cookies)โ•โ•โ•โ•> [Browser Ext] โ”€โ”€(127.0.0.1)โ”€โ”€> [Obsidian Vault] To eliminate this friction while upholding strict privacy boundaries and supply-chain integrity, I architected and open-sourced Canvas Sync Bridge v0.4.0โ€”a production-grade, hybrid local-first ecosystem split into two dedicated, decoupled open-source GitHub repositories and audited against official Obsidian Community guidelines. ...

September 18, 2026 ยท 10 min ยท 2047 words ยท Joshua Wortz

Hands-On AI Security: Red Teaming Piper with 5 Prompt Injection Vectors

How to probe and break local LLMs using Direct Injection, Roleplay, Obfuscation, and Authority Claims, demonstrating why system instructions fail as security boundaries.

September 17, 2026 ยท 3 min ยท 565 words ยท Joshua Wortz

Acuity Health: Part 2 โ€” Zero Trust DevSecOps & NIST SSDF

How to build an isolated, Zero Trust development architecture using ephemeral runners, proxy-scanned package caches, and NIST SP 800-218 practices without slowing engineering velocity.

September 15, 2026 ยท 6 min ยท 1263 words ยท Joshua Wortz

Bridging the Browser-to-Boundary Gap: From Client-Side SPA State Reconnaissance to Safe Harbor Verification

๐Ÿ” The Modern SPA Testing Paradox For more than two decades, the standard operating procedure for web application security assessments has centered around the interception proxy. Tools like Burp Suite, OWASP ZAP, and Caido position themselves between the browser and the target origin, capturing every HTTP request and response traversing the network socket. In traditional server-rendered architectures (PHP, ASP.NET, Rails), this model was nearly exhaustive: every routing decision, session transition, and authorization challenge occurred strictly across the wire. ...

September 12, 2026 ยท 11 min ยท 2188 words ยท Joshua Wortz

Hands-On AI Security: Building a Zero-Cost Local LLM Lab with Docker, Ollama, and Piper

How to build a 100% free, local AI security sandbox using Docker Desktop, Ollama (llama3.2), and a custom vulnerable chatbot to test prompt injection defenses without cloud API costs.

September 10, 2026 ยท 6 min ยท 1220 words ยท Joshua Wortz