This page shows the current focus. It is meant to show live professional movement, not a perfect finished picture: what is being studied, what is being practiced, and which evidence should appear next.

For the wider picture, see the Learning Roadmap.

Current Growth Focus

1
2
3
Security and Infrastructure
with GRC-aware documentation
and responsible AI-assisted workflows

Now

Linux, Networking and Web Security

  • Strengthening Linux foundations: users, groups, permissions, services, logs, backup basics, and hardening.
  • Systematizing networking fundamentals: TCP/IP, DNS, routing, switching, firewall basics.
  • Studying web security through HTTP, headers, auth/session concepts, and OWASP basics.
  • Turning labs into safe notes with clear scope and a defensive lesson.

Documentation and Evidence

  • Practicing the short format: context, scope, evidence, risk/control, next step.
  • Adding more checklists, decision records, and internal-style explainers.
  • Gradually expanding GitHub as a place for scripts, notes, and technical artifacts.
  • Separating facts, assumptions, limitations, and conclusions.

AI Workflows

  • Using AI for structure, drafts, and gap-finding.
  • Keeping the rule: AI helps, but does not replace validation.
  • Recording assumptions, limitations, and verification steps.

GRC and Risk

  • Learning to explain a technical finding through impact, risk, control, and decision.
  • Building language that works for engineering, management, and audit/GRC readers.
  • Practicing short executive summaries without exaggerated claims.

30-60 Day Goals

  • Add more practical GitHub artifacts.
  • Prepare a short note series on Linux/security foundations.
  • Prepare several networking notes with diagrams or troubleshooting logic.
  • Update evidence pages so they better show real proof points.
  • Write shorter, more concrete materials with a clear next step.

What Is Intentionally Not Here Yet

  • A separate resume page: it is better to collect more strong proof points first.
  • Loud senior-level claims without enough evidence base.
  • Aggressive consultant positioning without mature cases and outcomes.

Next Outputs

  • Linux/security checklist.
  • Networking fundamentals note.
  • GitHub artifact for small automation or documentation workflow.
  • GRC note about finding → risk → control.
  • Progress note at the end of the cycle: what worked, what was hard, what comes next.