Resume

Steven Foerster

Security Architect & Engineering Leader

Microsoft Security Response Center (MSRC) bug bounty recipient

Gainesville, VA steven@stevenfoerster.com LinkedIn GitHub

Summary

Security architect and engineering leader with 15+ years building production systems and leading the teams behind them, including five years as CTO taking GovCon Enclave from concept to the platform behind Rimstorm's acquisition. Chief Architect at BOOST LLC (a Brydon Group company), founder of Stormblest, and Microsoft Security Response Center (MSRC) bug bounty recipient. Deep background in secure platform architecture, vulnerability research, zero-trust networking, private/local-first AI infrastructure, CI/CD, and systems automation.

Recognition, Clearances & Certifications

MSRC bug bounty recipient. Former TS/SCI (2010–2023), CISSP (since 2021), OSCP, OSWP, eCXD.

Experience

BOOST LLC

Chief Architect

Jan 2026 – Present Herndon, VA

  • Led technology through acquisition by Brydon Group (PE), transitioning from startup CTO to Chief Architect of a PE-backed platform company, building on GovCon Enclave.
  • Architecting next-generation platform-scale delivery of secure enclave environments.
  • Leading secure platform architecture across the BOOST portfolio.

Rimstorm, Inc. (acquired by BOOST LLC in Jan 2026)

Chief Technology Officer

2021 – Jan 2026 Herndon, VA

  • Architected and led development of GovCon Enclave, a secure collaboration platform for protected data in regulated environments.
  • Built automation framework reducing enclave deployment from two weeks to two hours.
  • Scaled to 50+ enclaves supporting hundreds of users across SMB defense contractors.
  • Directed security design for access control, MFA enforcement, RBAC, and audit logging across enclaves.
  • Developed and tailored Kubernetes-based Wazuh SIEM handling 200k+ events per day from hundreds of endpoints.
  • Designed bastion access model (SSH key + MFA) and built Python API clients to idempotently configure and monitor platform services (Authentik, Apache Guacamole, Nextcloud, Mailcow, Samba AD).
  • Engineered low-level Linux platform components: custom SELinux module compilation, Layer 2 networking via ebtables across the Azure virtual fabric for systemd-nspawn containers, and advanced systemd orchestration (watchdogs, targets, custom services).
  • Designed and maintained GitLab CI/CD pipelines and secure developer tooling (Docker builds, artifact pipelines, FIPS cryptography enforcement) to build, test, and deploy containerized workloads.
  • Developed Ansible playbooks and custom concurrency wrappers for provisioning, configuration management, and patching across multiple cloud credentials and inventories, with state tracking, error handling, and failure recovery.
  • Partnered with executives and engineers to translate customer and operational requirements into the platform roadmap.
  • Mentored cross-functional teams in application security, automation, and secure DevOps practices.

Stormblest

Founder / Principal Engineer

2019 – Present

  • Created Mistborn (2020–2024, 25 releases), a secure open-source collaboration and zero-trust networking platform; featured in Linux Pro Magazine.
  • Built on Debian Linux + WireGuard, delivering services like Nextcloud, Jitsi, Vaultwarden, Apache Guacamole, Home Assistant, Jellyfin, Syncthing, Rocket.Chat, and Wazuh.
  • Designed with reproducible, scripted deployments to empower non-specialist admins.
  • Created open-source security and local-AI tools including Solux and Butler.
  • Developed Headscale + Traefik FIPS bundle, enabling secure overlay networks for edge deployments.
  • Contributed automation frameworks for Kubernetes, Docker/Podman Compose, and Linux systemd services.

REDLattice

Senior Software Engineer

2018 – 2021 Chantilly, VA

  • Built binary analysis and automation pipelines for advanced cyber operations.
  • Designed and built advanced testing harnesses for virtual and physical hardware.
  • Mentored junior engineers.
  • Maintained a TS/SCI clearance while supporting DoD and IC clients.

ManTech Cyber Advanced Research & Development (CARD)

Principal CNO Software Engineer

2015 – 2018 Reston, VA (acquired Oceans Edge in 2016)

  • Architected and built production-ready automation frameworks for network deployment, configuration management, and monitoring, integrating management/data planes with Zabbix health checks to ensure reliability at scale.
  • Trained and mentored customer-site engineers, ensuring adoption of new secure systems.
  • Maintained a TS/SCI clearance while supporting DoD and IC clients.

Lockheed Martin Advanced Technology Laboratories (ATL)

Computer Information Research Scientist (Engineering Leadership Development Program)

2009 – 2015 Manassas, VA and Arlington, VA

  • Earned Special Recognition Awards (2012, 2014, 2015) for algorithm development and software engineering.
  • Designed and trained neural networks for sonar image feature extraction; developed novel least squares and Gauss–Markov noise characterization methods; submitted IP on neural network architectures and multidimensional stochastic modeling.
  • Reverse-engineered algorithms, implemented sparse matrix optimizations reducing data size from 500 MB to 30 KB and runtime from hours to minutes, and created tools for high-fidelity statistical simulations and HDF5 data analysis.
  • Presented Feature Extraction of Sonar Grams at the NDIA Joint Undersea Warfare Technology Spring Conference (San Diego, 2010), bridging classical image processing with ANN-based methods.
  • Engineered software to deploy/test cyber ranges of 10,000+ virtual and physical nodes, advancing network simulation and cyber defense research.
  • Maintained a TS/SCI clearance while supporting DoD and IC clients.

Selected Projects & Products

GovCon Enclave

Secure enclave platform with automated deployment, SIEM, and bastion access.

Mistborn

Open-source zero-trust collaboration platform built on Linux + WireGuard + Docker; featured in Linux Pro Magazine.

Headscale-Headplane-Traefik Stack

Secure overlay network with custom DERP servers and FIPS-compliant proxies.

Solux

Local-first AI workflow engine: 30+ composable modules, YAML-defined workflows, RBAC, and MCP server mode; runs entirely on-prem with no cloud APIs.

Butler

Access-controlled reverse proxy for Ollama: API keys, JWT/OIDC auth, and per-user rate limiting for shared LLM inference.

CI/CD Automation

Ansible, Python, and Bash frameworks powering reproducible environments for enclaves, containers, and Linux systems.

Education

M.S., Computer Science

Georgia Institute of Technology

B.S., Electrical Engineering

Brigham Young University

Recognition

Certifications

Technical Skills

Linux

Debian, Rocky Linux, Arch, RHEL, Ubuntu; kernel modules, eBPF, Btrfs, systemd, automation

DevOps / CI/CD

Git, GitHub Actions, GitLab CI, Jenkins, Ansible, Docker, Podman, Kubernetes, Azure

Security infrastructure

Wazuh SIEM, Suricata, OpenVPN, WireGuard, FIPS 140-2/3 cryptography, post-quantum cryptography (ML-KEM/ML-DSA, NTRU)

Programming / Scripting

Python, Bash, Rust (kernel modules), Golang, Django, C, Java, ASM (x86+ARM)

Networking

Headscale/Tailscale, iptables/nftables, OpenVPN, WireGuard, zero-trust access

AI / ML

local LLM inference (Ollama), RAG pipelines, MCP, ONNX, LLM security (prompt injection testing, red teaming); neural networks and classical ML

Developer Productivity

reproducible environments, build systems, artifact pipelines, automation frameworks