Infrastructure that defends itself.
Loop Science is a hands-on consultancy for teams running serious infrastructure — AWS & GCP architecture, Kubernetes platforms, and the DevSecOps and IAM discipline that keeps it all defensible.
$ trivy image ghcr.io/loopscience/api:latest --severity HIGH,CRITICAL
$ ▊
Areas of expertise
Hands-on, from the kernel to the pipeline
Four disciplines that tend to show up together in every engagement.
Cloud architecture — AWS & GCP
Multi-account/org design, landing zones, and infrastructure-as-code that your team can actually read.
Kubernetes & container platforms
EKS, GKE, or self-managed clusters — sized, secured, and built to recover from failure before anyone needs to be paged.
DevSecOps
Security built into the pipeline, not bolted on after — from commit to production.
Identity & access management
Least-privilege by default, provable at audit time — not a spreadsheet nobody trusts.
Secure by design
The frameworks behind the buzzword
"Secure by design" gets used as an unexplained buzzword often enough that it's worth being specific. These are the actual frameworks engagements get built against.
NIST SSDF (SP 800-218)
The US government's secure-software-development framework, organized into four practice groups: prepare the organization (roles, training, tooling before code is written), protect the software (source and build integrity), produce well-secured software (design and implementation practices), and respond to vulnerabilities (a real disclosure and remediation process, not a contact-us form).
OWASP ASVS
A tiered, checklist-style verification standard for application security controls — L1 for opportunistic risks every app should close, L2 for apps handling sensitive data, L3 for the controls a high-value target actually needs. Naming the level up front turns "we did a security review" into a claim someone can actually audit.
SLSA (supply-chain levels)
Levels (0–3) for how provable and tamper-resistant your build pipeline actually is — who could have modified an artifact between source and deployment, and whether you could prove they didn't. This is the standard the SBOM/Syft/Grype tooling below exists to satisfy, not a separate concern from it.
CISA Secure by Design
Three published principles, not a vibe: take ownership of customer security outcomes (a breach from a default-insecure setting is the vendor's failure, not the user's), embrace radical transparency and accountability (real CVE disclosure, real postmortems), and lead from the top (security as a business priority set by leadership, not delegated entirely to one engineer).
The toolchain
What's actually in the toolchain
What "DevSecOps" actually means in this practice, grouped by where each tool sits in the stack.
The filter underneath the list: does this tool answer to an open specification, or to one vendor's roadmap? OAuth2, OpenID Connect, SAML, and Open Policy Agent's Rego are published standards any vendor can implement; a proprietary identity or policy control plane tied to one company's API isn't, and that's a lock-in risk as much as a technical one.
Identity & zero trust
SSO and zero-trust access control, from the identity provider to the proxy sitting in front of every internal service.
Policy & runtime enforcement
Policy-as-code and mTLS enforced at the mesh layer, not just checked at the edge and trusted after that.
Supply chain security
Know what's actually in your build, and catch what's wrong with it before it ships, not after an audit asks.
CI/CD & infrastructure as code
Where policy actually gets enforced — in the pipeline, gating a merge, not in a document nobody rereads.
Selected engagements
Work delivered across cloud, platform & engineering teams
A sample of past engagements, spanning technical leadership to consulting and engineering.
DevOps / Engineering / CTO · US
DevOps / Engineering · US
DevOps / Engineering · US
DevOps / Engineering · US
DevOps · Australia
Consulting / CTO · US
DevOps · Spain
DevOps / Engineering · US
DevOps / Engineering · US
Engineering · US
Consulting / Project Management · Australia
Consulting / Project Management · Australia
DevOps / Engineering · US
DevOps · US
DevOps / Engineering · US
DevOps / Engineering · US
Consulting · US
DevOps · US
Engineering · US
Hextrap
Platform Eng / AI Tooling · US
Expiring.at
Platform Eng / AI Tooling · US
Consulting · US
How we work
Fixed scope. Direct access. No relay.
Assess
Architecture, IAM, and pipeline review against real threat models — not a generic checklist. Fixed scope, written up front.
Build
Infrastructure as code, reviewed in the open. You get a direct line to the engineer doing the work — always.
Operate
We stay on for hosting, monitoring, and hardening as things evolve — billed simply through your Loop Science account.
Designed so the pager doesn't have to ring
The goal isn't faster incident response — it's systems that catch and correct their own failures before a human needs to. Loop Science builds on proven cloud-native resilience (redundancy, graceful degradation, auto-scaling, circuit breakers) and layers AI-driven anomaly detection and automated remediation on top, so a 3am page is the exception, not the operating model.
// autoremediate.yaml
on: alert.triggered
when:
severity: high
pattern: known_signature
actions:
- run: playbook/restart_pod
- run: playbook/scale_out
- escalate: if unresolved_after(10m)
Have infrastructure to build, fix, secure, or scale?
Existing client? Log in to your account. New engagement? Tell us about it and grab time on the calendar.