visitor · resolving…
Senior Cyber Security Engineer

Michael
Nancarrow

Profile
role: senior cyber security engineer
location: brisbane, qld, au
focus: zero trust · edr · iam · ai security
visitor: resolving…
products: burnerchat 1.0.2 · open model responder 1.0.2
Praying hands before a cross

Enterprise-scale Cyber Security, Identity, and Network Controls practitioner. Designing and operating security programs across multi-cloud environments — implementing AI-assisted tooling for accelerated threat response, containment, and compliance. Designer of BurnerChat and Open Model Responder.

8,500
Users
9,000+
Endpoints
Multi-Cloud
Infrastructure
300+
Locations
About

About Me

Senior Cyber Security Engineer with over a decade of progressive experience across zero trust architecture, endpoint detection and response, and identity and access management. Currently securing the technology estate at Eagers Automotive (ASX: APE), one of Australia's largest automotive dealer groups — operating at scale across 8,500 users, 9,000+ endpoints, and 300+ locations.

I design and build security tooling alongside enterprise responsibilities — from sanctioned breach simulation platforms to cryptographic messaging applications — with a preference for minimal, auditable implementations over feature-rich complexity. Production products include BurnerChat (end-to-end encrypted messaging) and Open Model Responder / AI Konoha (local-first response enablement).

Operator of hardened multi-OS environments across CachyOS, macOS, and Qubes OS. Advocate for data sovereignty, local-first AI, and privacy by design.

Location
Brisbane, Queensland, Australia
Current role
Senior Cyber Security Engineer · Eagers Automotive (APE)
Focus areas
Zero Trust · EDR/XDR · IAM · Network Security · AI Infrastructure
Production
BurnerChat v1.0.2 · Open Model Responder v1.0.2
Operating environments
CachyOS · macOS · Qubes OS
Production

BurnerChat E2E ENCRYPTED

Production · Version 1.0.2 · burnerchat.org

Production v1.0.2 Go 1.22 macOS 11+ Linux

A self-contained cryptographic messaging platform engineered for operational environments where transport-layer trust cannot be assumed. Messages are encoded as authenticated, channel-agnostic tokens via memory-hard key derivation and AEAD encryption, then decoded exclusively on the recipient's device. The architecture eliminates all centralised infrastructure dependencies by design: no relay, no registration, no telemetry surface.

Operational Independence
Operates entirely on-device with no server registration, no centralised relay, and no analytics pipeline. The threat model makes no trust assumptions about transport infrastructure or third-party service availability.
Authenticated Encryption
Argon2id key derivation with ChaCha20-Poly1305 AEAD and ISO/IEC 7816-4 compliant padding. Ciphertext length normalisation into 256-byte boundary clusters defeats length-based traffic correlation.
Tor v3 Hidden-Service Transport
Integrated Tor v3 onion hidden-service providing peer-to-peer token delivery without a third-party relay. In-memory ring-buffer design ensures zero ciphertext persistence beyond the active session.
Secure File Transfer
Integrated CryptShare v2 pipeline: automated PII detection, metadata sanitisation, double-layered encryption (Argon2id, ChaCha20-Poly1305, AES-256-GCM). Plaintext shredded immediately post-encryption. Three delivery channels: direct download, Tor mailbox, or single-use TorShare v3 onion link.
Scriptable CLI
Exposes the full encode and decode pipeline via burnerchatcli for integration into scripted security workflows and automation pipelines. Identical key derivation and wire format as the GUI — no interactive dependencies.
Authenticated Local Interface
Embedded HTML/CSS UI served on a randomly bound loopback port with mandatory per-session authentication tokens. Unauthenticated local callers rejected at the HTTP layer. Native system tray integration via CGO on Linux and macOS.
Go 1.22 Argon2id ChaCha20-Poly1305 AES-256-GCM bbolt Tor v3 Python / CryptShare BLAKE3 CGO / GTK3 Ayatana AppIndicator
Production

Open Model Responder / AI Konoha

Production · Version 1.0.2 · openmodelresponder.org

Production v1.0.2 Python Windows macOS Linux

Local-first general response and enablement assistant. Paste a request or message and receive a thorough, formatted reply — Ollama by default, with optional OpenVINO GenAI on Intel NPU and optional cloud writers. Built for operators who need depth, citations, and tone without defaulting sensitive material to a random cloud chat.

Local-First Pipeline
Triage → knowledge-base and document match → writer → polish runs on the workstation. Ollama is the default inference path; cloud writers remain opt-in.
Operator Onboarding
First-run wizard captures role, function, and privacy preferences. Usage password is separate from the URL token; optional click-through demo after setup.
Token-Gated UI
Loopback browser interface with session authentication. Designed for single-operator workstation use — not multi-tenant SaaS.
Optional Accelerators
OpenVINO GenAI path for Intel NPU when selected and healthy. Core install does not require OpenVINO or cloud credentials.
Operational Controls
High-assurance install lifecycle including remote killswitch coordination for fielded builds. Ownership unlock via verified donation after trial window.
Cross-Platform Packaging
Windows, macOS, and Linux support with install scripts and optional PyInstaller distribution builds for operator deployment.
Python Ollama Local LLM OpenVINO GenAI Loopback UI MCP Claude Skills
Production

OS Hardening and AI Guardrails

Production suite · Private tooling

Production macOS 11+ CachyOS / Arch Bash Python Private

Automated security baseline enforcement and privacy hardening across macOS and CachyOS/Arch Linux, paired with architectural guardrails that govern how AI tooling interacts with enterprise and personal security boundaries. Dual-platform suite for high-assurance workstation environments where configuration integrity is operationally critical.

macOS System Controls
Applies native macOS security primitives (csrutil, spctl, socketfilterfw, defaults) for System Integrity Protection management, Gatekeeper policy enforcement, kernel extension control, and application firewall configuration.
Telemetry Suppression
Targeted suppression of OS-level telemetry, diagnostic reporting, and phone-home behaviour on macOS. Per-application privacy permission hardening, analytics opt-out enforcement, and managed preference deployment.
CachyOS Hardening Daemon
Persistent systemd service providing kernel parameter hardening via sysctl, service attack surface reduction, filesystem permission enforcement, and mount option hardening across CachyOS and Arch Linux installations.
Network and Firewall Controls
Outbound connection filtering and application-layer firewall policy management across both platforms. macOS socketfilterfw integration and Linux nftables/netfilter rule authoring with structured policy auditing.
Drift Detection and Remediation
Continuous enforcement mode with automated configuration drift detection. System-level changes trigger re-evaluation and re-application of the hardening baseline without manual operator intervention.
AI Architectural Guardrails
Policy framework governing how local and assisted AI tooling interacts with security boundaries — permission scopes, data handling constraints, and regression controls so AI behaviour stays within defined operational limits.
Bash Python systemd csrutil spctl socketfilterfw sysctl nftables AI Safety Policy CachyOS / Arch
Operator Tools

Operator Tools

Breach

Python BAS Private

Sanctioned breach simulation and security control validation tooling for enterprise environments. BAS-style testing with auditable outputs for validating detection, containment, and response controls under controlled conditions.

Control Validation
Structured exercises that exercise enterprise security controls and produce evidence suitable for assurance and remediation tracking.
Auditable Outputs
Results formatted for operator review and programme reporting — not opaque black-box scoring.
Enterprise Scope
Designed for sanctioned testing within defined organisational boundaries and change-control processes.
Python BAS Control Validation

Control D

Python DNS Private

DNS control plane tooling for encrypted DNS management, custom blocklist automation, and family / IoT / C2 filtering via Control D — with UniFi integration for edge policy.

Encrypted DNS Management
Operational control of Control D profiles and resolvers for workstation and network-edge filtering.
Blocklist Automation
Custom list maintenance for family protection, IoT isolation, and known C2 / malware domains.
UniFi Integration
Coordinates DNS policy with UniFi network infrastructure for consistent edge enforcement.
ControlD DNS Python UniFi

Stock Inventory

v1.1 Python Linux macOS Private

Local-first supply and consumables tracker. Encrypted SQLite catalog with CLI and localhost browser UI — designed for household, workshop, and small-business inventory without a SaaS account or always-on server.

Encrypted Local Database
SQLite-backed catalog and transactions with encryption at rest; optional iCloud-aware path resolution on macOS for cross-device sync without a custom backend.
CLI and Localhost UI
Full stockmon CLI for catalog, transactions, reports, and import — plus a loopback web UI for day-to-day operation.
Low-Stock and Reporting
Threshold-aware low-stock views and reporting for consumables replenishment without cloud telemetry.
Python SQLite FastAPI stockmon Local-first

Network Monitoring

v1.9 Python Linux Private

Localhost network health dashboard. Consecutive DNS, HTTPS, ICMP, TCP, route, and speedtest probes with SQLite history, issue highlighting, diagnostic suites, and executive reporting — for operators who need comparable measurements on the workstation itself.

Probe Cycles
Scheduled probe cycles against a built-in regional catalog plus custom targets; results stored in SQLite for trend comparison.
Status-First Dashboard
Local FastAPI UI with Home, Services, Diagnostics, Report, Tests, and Settings layers — light/dark theme, honest labelling of VPN/TOR and filtered ICMP noise.
Reports and Test Packs
In-app executive report with JSON download, JSON test-pack import with expected-result comparison, and proactive diagnostic bundles.
Python FastAPI SQLite netmon DNS / ICMP / HTTPS
Skills

Tech Stack

Zero Trust / Networking
Zscaler ZIAZscaler ZPAZCC Cloudflare ZTUniFiControlD DNS
Endpoint / EDR / XDR
SentinelOneCrowdStrike Microsoft Defender XDRFortiSaaS Palo AltoMicrosoft Intune
Identity / IAM
Microsoft Entra IDConditional Access MFARBAC
DevSecOps
GitLab CI/CDPythonGo BashMCPClaude Code
AI Infrastructure
OllamaLocal LLMLiteLLM AWS BedrockVertex AI
Systems / OS
CachyOS / ArchQubes OS macOSFedoraUbuntu
Experience

Work History

Senior Cyber Security Engineer
Current
Eagers Automotive Limited (ASX: APE) · Brisbane, QLD
Enterprise cyber security engineering across one of Australia's largest automotive dealer groups. Responsible for zero trust network architecture (Zscaler ZIA/ZPA/ZCC), endpoint detection and response (SentinelOne), and identity governance (Microsoft Entra ID and Intune) at scale across 8,500 users, 9,000+ endpoints, and 300+ locations. Developing AI-assisted tooling for accelerated threat response and compliance. Leading threat detection, incident response, and security control validation programs.
Zscaler ZIAZscaler ZPAZCC SentinelOneCrowdStrike Palo AltoMicrosoft Defender XDR FortiSaaSEntra ID IntuneGitLab CI/CDPython
IT Security Solutions Engineer
Past Role
AP Eagers Limited · Brisbane, QLD
Security solutions architecture and implementation across the Eagers automotive group. Progressed through senior IT functions including System Administrator, Network Administrator, and Manager of Information Technology before transitioning into a dedicated security engineering role. Designed enterprise security controls, managed IT security vendors, and developed policies governing the organisation's security posture.
Palo AltoFirewall Management Security ArchitectureNetwork Administration IT ManagementVendor Management System Administration
Owner / IT Consultant
Past Role
Nancarrow Consulting · Brisbane, QLD
Independent IT consultancy serving small business and home user environments. Scope covered designing, building, optimising, and troubleshooting technology stacks across networking, systems, procurement, and ongoing operational support.
IT ConsultingSMB NetworkingTechnical Support
Bachelor of Networking
2016
Aurora Training Institute · Brisbane, QLD
Bachelor's degree in Networking. Ongoing professional development across cybersecurity engineering and cloud security — see Latest Education section.
Latest Education

Ongoing Learning

Actively pursuing formal education aligned to current enterprise threat landscapes. Recent completions span practical cybersecurity engineering methodology (Team Blue, 2024) and Google's professional-level security program (2025). Currently working toward CISSP certification — ISC²'s gold-standard for senior security practitioners.

ISC²
CISSP — Certified Information Systems Security Professional
Eight-domain advanced security certification spanning security and risk management, asset security, security engineering, network security, IAM, security assessment, operations, and software development security.
In Progress — 2026
Google
Cybersecurity Professional Certificate
Covers network security, SIEM operations, threat detection and analysis, vulnerability management, incident response frameworks, and Python automation for security workflows. Part of Google's professional certification track.
Issued: 2025
Team Blue
Cybersecurity Engineer
Structured program covering blue team operations, threat detection methodologies, defensive security control design, and incident response within enterprise environments. Practical focus on applied cyber defence.
Issued: 2024
Niche Projects

Niche Projects

Vultr / ControlD Orchestration
Private
Infrastructure and DNS orchestration across Vultr compute and Control D policy planes — automation for provisioning, resolver profiles, and edge filtering consistency.
VultrControlDPythonDNS
TCG Grading Companies
Private
Operator tooling around TCG grading workflows — assessment UX, lifecycle tracking, and reporting for grading company operations.
TCGWorkflowPythonUX
AI Audit and Report Log
Private
Audit trail and reporting for AI-assisted operator sessions — capture, structure, and review AI tool usage for accountability and post-incident analysis.
AI AuditLoggingCompliancePython