Resume
Steven Foerster
Security Architect & Engineering Leader
Microsoft Security Response Center (MSRC) bug bounty recipient
Gainesville, VA steven@stevenfoerster.com LinkedIn GitHub
Summary
Security architect and engineering leader with 15+ years building production systems and leading the teams behind them, including five years as CTO taking GovCon Enclave from concept to the platform behind Rimstorm's acquisition. Chief Architect at BOOST LLC (a Brydon Group company), founder of Stormblest, and Microsoft Security Response Center (MSRC) bug bounty recipient. Deep background in secure platform architecture, vulnerability research, zero-trust networking, private/local-first AI infrastructure, CI/CD, and systems automation.
Recognition, Clearances & Certifications
MSRC bug bounty recipient. Former TS/SCI (2010–2023), CISSP (since 2021), OSCP, OSWP, eCXD.
Experience
BOOST LLC
Chief Architect
Jan 2026 – Present Herndon, VA
- Led technology through acquisition by Brydon Group (PE), transitioning from startup CTO to Chief Architect of a PE-backed platform company, building on GovCon Enclave.
- Architecting next-generation platform-scale delivery of secure enclave environments.
- Leading secure platform architecture across the BOOST portfolio.
Rimstorm, Inc. (acquired by BOOST LLC in Jan 2026)
Chief Technology Officer
2021 – Jan 2026 Herndon, VA
- Architected and led development of GovCon Enclave, a secure collaboration platform for protected data in regulated environments.
- Built automation framework reducing enclave deployment from two weeks to two hours.
- Scaled to 50+ enclaves supporting hundreds of users across SMB defense contractors.
- Directed security design for access control, MFA enforcement, RBAC, and audit logging across enclaves.
- Developed and tailored Kubernetes-based Wazuh SIEM handling 200k+ events per day from hundreds of endpoints.
- Designed bastion access model (SSH key + MFA) and built Python API clients to idempotently configure and monitor platform services (Authentik, Apache Guacamole, Nextcloud, Mailcow, Samba AD).
- Engineered low-level Linux platform components: custom SELinux module compilation, Layer 2 networking via ebtables across the Azure virtual fabric for systemd-nspawn containers, and advanced systemd orchestration (watchdogs, targets, custom services).
- Designed and maintained GitLab CI/CD pipelines and secure developer tooling (Docker builds, artifact pipelines, FIPS cryptography enforcement) to build, test, and deploy containerized workloads.
- Developed Ansible playbooks and custom concurrency wrappers for provisioning, configuration management, and patching across multiple cloud credentials and inventories, with state tracking, error handling, and failure recovery.
- Partnered with executives and engineers to translate customer and operational requirements into the platform roadmap.
- Mentored cross-functional teams in application security, automation, and secure DevOps practices.
Stormblest
Founder / Principal Engineer
2019 – Present
- Created Mistborn (2020–2024, 25 releases), a secure open-source collaboration and zero-trust networking platform; featured in Linux Pro Magazine.
- Built on Debian Linux + WireGuard, delivering services like Nextcloud, Jitsi, Vaultwarden, Apache Guacamole, Home Assistant, Jellyfin, Syncthing, Rocket.Chat, and Wazuh.
- Designed with reproducible, scripted deployments to empower non-specialist admins.
- Created open-source security and local-AI tools including Solux and Butler.
- Developed Headscale + Traefik FIPS bundle, enabling secure overlay networks for edge deployments.
- Contributed automation frameworks for Kubernetes, Docker/Podman Compose, and Linux systemd services.
REDLattice
Senior Software Engineer
2018 – 2021 Chantilly, VA
- Built binary analysis and automation pipelines for advanced cyber operations.
- Designed and built advanced testing harnesses for virtual and physical hardware.
- Mentored junior engineers.
- Maintained a TS/SCI clearance while supporting DoD and IC clients.
ManTech Cyber Advanced Research & Development (CARD)
Principal CNO Software Engineer
2015 – 2018 Reston, VA (acquired Oceans Edge in 2016)
- Architected and built production-ready automation frameworks for network deployment, configuration management, and monitoring, integrating management/data planes with Zabbix health checks to ensure reliability at scale.
- Trained and mentored customer-site engineers, ensuring adoption of new secure systems.
- Maintained a TS/SCI clearance while supporting DoD and IC clients.
Lockheed Martin Advanced Technology Laboratories (ATL)
Computer Information Research Scientist (Engineering Leadership Development Program)
2009 – 2015 Manassas, VA and Arlington, VA
- Earned Special Recognition Awards (2012, 2014, 2015) for algorithm development and software engineering.
- Designed and trained neural networks for sonar image feature extraction; developed novel least squares and Gauss–Markov noise characterization methods; submitted IP on neural network architectures and multidimensional stochastic modeling.
- Reverse-engineered algorithms, implemented sparse matrix optimizations reducing data size from 500 MB to 30 KB and runtime from hours to minutes, and created tools for high-fidelity statistical simulations and HDF5 data analysis.
- Presented Feature Extraction of Sonar Grams at the NDIA Joint Undersea Warfare Technology Spring Conference (San Diego, 2010), bridging classical image processing with ANN-based methods.
- Engineered software to deploy/test cyber ranges of 10,000+ virtual and physical nodes, advancing network simulation and cyber defense research.
- Maintained a TS/SCI clearance while supporting DoD and IC clients.
Selected Projects & Products
GovCon Enclave
Secure enclave platform with automated deployment, SIEM, and bastion access.
Mistborn
Open-source zero-trust collaboration platform built on Linux + WireGuard + Docker; featured in Linux Pro Magazine.
Headscale-Headplane-Traefik Stack
Secure overlay network with custom DERP servers and FIPS-compliant proxies.
Solux
Local-first AI workflow engine: 30+ composable modules, YAML-defined workflows, RBAC, and MCP server mode; runs entirely on-prem with no cloud APIs.
Butler
Access-controlled reverse proxy for Ollama: API keys, JWT/OIDC auth, and per-user rate limiting for shared LLM inference.
CI/CD Automation
Ansible, Python, and Bash frameworks powering reproducible environments for enclaves, containers, and Linux systems.
Education
M.S., Computer Science
Georgia Institute of Technology
B.S., Electrical Engineering
Brigham Young University
Recognition
- Microsoft Security Response Center (MSRC) bug bounty recipient and 2026 Special Mention
Certifications
- CISSP (Certified Information Systems Security Professional) - Active; issued Sep 15, 2021; expires Sep 30, 2027
- OSCP (Offensive Security Certified Professional) - Active; issued May 22, 2021; does not expire
- OSWP (Offensive Security Wireless Professional) - Active; issued Sep 4, 2021; does not expire
- eCXD (eLearnSecurity Certified eXploit Developer) - Active; issued May 3, 2022; does not expire
Technical Skills
Linux
Debian, Rocky Linux, Arch, RHEL, Ubuntu; kernel modules, eBPF, Btrfs, systemd, automation
DevOps / CI/CD
Git, GitHub Actions, GitLab CI, Jenkins, Ansible, Docker, Podman, Kubernetes, Azure
Security infrastructure
Wazuh SIEM, Suricata, OpenVPN, WireGuard, FIPS 140-2/3 cryptography, post-quantum cryptography (ML-KEM/ML-DSA, NTRU)
Programming / Scripting
Python, Bash, Rust (kernel modules), Golang, Django, C, Java, ASM (x86+ARM)
Networking
Headscale/Tailscale, iptables/nftables, OpenVPN, WireGuard, zero-trust access
AI / ML
local LLM inference (Ollama), RAG pipelines, MCP, ONNX, LLM security (prompt injection testing, red teaming); neural networks and classical ML
Developer Productivity
reproducible environments, build systems, artifact pipelines, automation frameworks