Skip to content
View wz-gsa's full-sized avatar

Block or report wz-gsa

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
wz-gsa/README.md

William Zujkowski

GSA · Cloud.gov — work account

Cloud.gov (FedRAMP Moderate) Security & Risk Mitigation AI Enablement for Defenders


About

Senior Security Engineer at Cloud.gov, a FedRAMP Moderate Platform-as-a-Service for federal agencies.

I work on security and risk mitigation for Cloud.gov, a platform federal agencies rely on.

To accelerate that work, I build practical agentic-AI tooling and instructions that give senior engineers a safe, fast path to do more: guardrails, sandbox isolation, least-privilege credentials, and compliance-as-code baked into the tools they already use — so development, operations, and security teams can keep pace with adversaries already moving at machine speed. The goal is to make the secure path the default path.

This is my GSA work account. Work here is done in that capacity.


What I'm Building

  • Security & risk mitigation for Cloud.gov — hardening a FedRAMP Moderate PaaS: secure-by-design architecture, continuous monitoring, and reducing risk across the platform federal agencies rely on.
  • Practical agentic-AI tooling for engineers — sandboxed, least-privilege environments for AI coding agents (secret handling that keeps real credentials out of the agent's reach, egress locked to an allow-list) so senior engineers can safely accelerate the mission.
  • Federal AI guidance as executable standards — turning NIST (800-53, 800-218A) and federal AI policy into automated, verifiable checks instead of PDFs.

Tech

Python Bash Docker GitHub Actions


Focus Areas

role: Senior Security Engineer @ Cloud.gov (GSA)
mission: Security & risk mitigation for Cloud.gov
approach: Practical agentic-AI tooling that lets engineers accelerate that mission safely
focus:
  - Secure-by-design architecture & risk reduction on a FedRAMP Moderate PaaS
  - Safe execution environments for agentic AI (sandbox isolation, least privilege)
  - Federal AI guidance turned into compliance-as-code
  - Helping dev / ops / security teams keep pace with AI-era threats

Popular repositories Loading

  1. wz-gsa wz-gsa Public

    Config files for my GitHub profile.

  2. watchtower watchtower Public

    Forked from GSA-TTS/watchtower

    A run-anywhere, Cloud Foundry drift detection service.

    Go