Skip to content
View davidmatousek's full-sized avatar
🎯
Focusing
🎯
Focusing

Highlights

  • Pro

Organizations

@GitHubDevopsIOS

Block or report davidmatousek

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
davidmatousek/README.md

David Matousek

Cybersecurity Leader · Application, AI & Cloud Security · Risk & Compliance

I don't just advise on security — I build it. Creator of tachi and AOD.

I lead enterprise security programs where strategy meets engineering — across application security, AI/ML security, and cloud security, grounded in the risk, compliance, and governance discipline that regulated environments demand. Today I lead compliance, risk, and security architecture for the Commonwealth of Massachusetts' Business Enterprise System Transformation (BEST) program, and I've served as a fractional CISO bringing senior security leadership to organizations that need it without a full-time hire.

What sets me apart is range: I pair executive security leadership with the hands-on technical depth a modern CISO or VP of Cybersecurity role demands.


Security leadership

  • Enterprise risk, compliance & security architecture — Lead compliance, risk, and security architecture for the Commonwealth of Massachusetts' Business Enterprise System Transformation (BEST) program.
  • Fractional CISO — Bring CISO-level security leadership to organizations that need it without a full-time hire.
  • Application, AI & cloud security — Secure modern application, AI-agent, and cloud workloads through threat modeling, secure-by-design architecture, and governance.
  • Security strategy & governance — Translate risk and compliance requirements into security architecture and program governance for regulated, AI-forward environments.

What I build

I build the tooling I'd deploy on my own security team — practical, governed, and verifiable.

tachi — flagship project Threat Modeling and Vulnerability Detection Harness for Claude Code. An AI-reasoning security scanner (STRIDE + AI + MAESTRO) that reasons over your architecture to catch the logic-level risks SAST can't reach. OWASP 50/50 coverage across LLM 2025, Agentic 2026, ML 2023, Mobile 2024, and Web/API 2021/2023 — every catalogued threat in all five frameworks has a detection agent, with byte-deterministic, reproducible verification.

AOD — Agentic Oriented Development · newly launched An open-source methodology and toolkit for governed AI-assisted development: a three-role Triad (PM · Architect · Team-Lead) and a six-stage lifecycle that produce specs an agent can't bypass at build time. Ships with stack packs, Claude-led security scanning, and structured thinking lenses. (GitHub)

Writing & frameworks

  • Cybersecurity Content — The Security Manifesto for AI-assisted development and the Seven Strategic Cybersecurity Posture Domains framework.
  • Agentic-Oriented Development — My book series and the Agentic Shift newsletter on agentic development. Subscribe on LinkedIn

More on GitHub

Smaller builds that keep me close to the code:

Repo What it does
GitHubDevOps SwiftUI app for GitHub CI/CD metrics via the GraphQL API.
StockWatcher Swift application for stock watching via Alpha Vantage.

Let's connect

GitHub LinkedIn

Pinned Loading

  1. tachi tachi Public

    Threat modeling and AI-reasoning vulnerability detection harness for Claude Code — STRIDE + AI + MAESTRO

    Python 73 17

  2. agentic-oriented-development-kit agentic-oriented-development-kit Public

    ADLC Triad governance template for AI agent-assisted development

    Shell 18 4