Michael
Nancarrow
Enterprise-scale Cyber Security, Identity, and Network Controls practitioner. Designing and operating security programs across multi-cloud environments — implementing AI-assisted tooling for accelerated threat response, containment, and compliance. Designer of BurnerChat and Open Model Responder.
About Me
Senior Cyber Security Engineer with over a decade of progressive experience across zero trust architecture, endpoint detection and response, and identity and access management. Currently securing the technology estate at Eagers Automotive (ASX: APE), one of Australia's largest automotive dealer groups — operating at scale across 8,500 users, 9,000+ endpoints, and 300+ locations.
I design and build security tooling alongside enterprise responsibilities — from sanctioned breach simulation platforms to cryptographic messaging applications — with a preference for minimal, auditable implementations over feature-rich complexity. Production products include BurnerChat (end-to-end encrypted messaging) and Open Model Responder / AI Konoha (local-first response enablement).
Operator of hardened multi-OS environments across CachyOS, macOS, and Qubes OS. Advocate for data sovereignty, local-first AI, and privacy by design.
BurnerChat E2E ENCRYPTED
Production · Version 1.0.2 · burnerchat.org
A self-contained cryptographic messaging platform engineered for operational environments where transport-layer trust cannot be assumed. Messages are encoded as authenticated, channel-agnostic tokens via memory-hard key derivation and AEAD encryption, then decoded exclusively on the recipient's device. The architecture eliminates all centralised infrastructure dependencies by design: no relay, no registration, no telemetry surface.
Open Model Responder / AI Konoha
Production · Version 1.0.2 · openmodelresponder.org
Local-first general response and enablement assistant. Paste a request or message and receive a thorough, formatted reply — Ollama by default, with optional OpenVINO GenAI on Intel NPU and optional cloud writers. Built for operators who need depth, citations, and tone without defaulting sensitive material to a random cloud chat.
OS Hardening and AI Guardrails
Production suite · Private tooling
Automated security baseline enforcement and privacy hardening across macOS and CachyOS/Arch Linux, paired with architectural guardrails that govern how AI tooling interacts with enterprise and personal security boundaries. Dual-platform suite for high-assurance workstation environments where configuration integrity is operationally critical.
Operator Tools
Breach
Sanctioned breach simulation and security control validation tooling for enterprise environments. BAS-style testing with auditable outputs for validating detection, containment, and response controls under controlled conditions.
Control D
DNS control plane tooling for encrypted DNS management, custom blocklist automation, and family / IoT / C2 filtering via Control D — with UniFi integration for edge policy.
Stock Inventory
Local-first supply and consumables tracker. Encrypted SQLite catalog with CLI and localhost browser UI — designed for household, workshop, and small-business inventory without a SaaS account or always-on server.
Network Monitoring
Localhost network health dashboard. Consecutive DNS, HTTPS, ICMP, TCP, route, and speedtest probes with SQLite history, issue highlighting, diagnostic suites, and executive reporting — for operators who need comparable measurements on the workstation itself.
Tech Stack
Work History
Ongoing Learning
Actively pursuing formal education aligned to current enterprise threat landscapes. Recent completions span practical cybersecurity engineering methodology (Team Blue, 2024) and Google's professional-level security program (2025). Currently working toward CISSP certification — ISC²'s gold-standard for senior security practitioners.