hi —
Noah Stanford
security engineer and leader
building and hacking systems for 15+ years
about
Built SpaceX's passwordless authentication stack for 10,000+ users, served as security SME for AWS Cognito across 7 service teams / 100+ engineers, and built YC-backed security products spanning FIDO2, PKI, TLS inspection, network and browser security.
skills
identity
01WebAuthn / FIDO2SAML & OIDC
PKI & mTLSPIV & smart cards
workload identityOPA, Cedar
security
02product securitythreat modeling
endpoint securitynetwork security
DLPOT / manufacturing
systems
03LinuxWindows / WFP
containersmicroVMs
Kubernetes
engineering
04PythonC++
GoTypeScript
AWS & Azure
Founder & CEO @ Repacket
2024 — now
- Led architecture and wrote production C++ for a cross-platform endpoint TLS-inspection proxy with OS-level network integration, native HTTP/2 support, and tested throughput above 1 Gbps.
- Built JavaScript security controls injected into web pages, including LLM-powered phishing detection and DLP that blocked sensitive uploads (PII, PHI, etc) using natural-language policies.
- Created a per-device certificate authority that dynamically issued certificates for intercepted sites, keeping TLS inspection keys on customer endpoints rather than on Repacket servers.
- Led 8 cross-functional contributors across engineering and operations while remaining hands-on in architecture and core product engineering.
- Led SOC 2 Type II and ISO 27001 security/compliance programs, coordinating engineering, operations, auditors, and third-party vendors.
- Owned IT and security spanning multiple AWS accounts (ECS, EKS, RDS, IAM), endpoint management, Corgea, CrowdStrike, Okta, Google Workspace, WebAuthn/FIDO2 and Tailscale
Founder & CEO, Lead Engineer @ 0pass (YC W23)
2023 — 2024
- Built a passwordless authentication platform from MVP through production, including Python web applications and a Python/Qt desktop client for Windows, macOS, and Linux.
- Implemented FIDO2/WebAuthn authentication and SAML federation with IdPs like ADFS and Okta, enabling passwordless login for enterprise applications.
- Built YubiKey enrollment and PIV certificate provisioning for hardware-backed OS login and remote access across Windows/Active Directory, macOS, Linux PAM, SSH, and RDP.
- Integrated HashiCorp Vault and customer-managed certificate authorities, supporting self-hosted and air-gapped deployments for government, defense, & high-security customers.
Lead Security Engineer, AWS Cognito @ Amazon Web Services
2022
- Primary security SME for AWS Cognito across 7 service teams / 100+ engineers; established security roadmap, vulnerability triage, and embedded security ownership across service teams.
- Triaged incoming security reports across Cognito, including high-severity vulnerabilities.
- Helped build early security team and security guardian program for AWS Cognito software engineers.
- Threat modeled SMS pumping abuse driving up to $40K/month in customer charges; designed country-based enrollment controls to limit fraudulent SMS traffic.
Lead Security Engineer, Identity @ SpaceX
2020 — 2022
- Built SpaceID, SpaceX's passwordless authentication stack, and led its deployment across web, Windows, macOS, and Linux for 10,000+ users; personally built core features, coordinated principal engineers, owned the technical roadmap, and drove executive alignment.
- Restored command-and-control for 2,000+ Starlink satellites during an outage.
- Built Palo Alto firewall automation and SOC tooling, and owned production SIEM alerting infrastructure (ElastAlert).
- Threat modeled software and critical infrastructure, including Dragon crew-training access, Velo3D and other manufacturing systems, and Mission network segmentation and isolation.
- Red-teamed commercial EDR platforms (XDR, S1, Falcon) during vendor evaluations using LOTL techniques and commercial implants, testing detection and prevention capabilities.
Founder & CTO @ Eleon LLC
2016 — 2020
- Built the majority of a production application stack serving thousands of daily users, spanning Spring APIs, full-stack web, payments, databases, security tools, and deployment infrastructure.
- Designed a centralized API with 50+ endpoints and 100+ database operations, including connection pooling, authentication, reusable query abstractions, and cross-app services.
- Led 5–10 software engineers and technical strategy for production systems supporting 2,000+ concurrent users and nearly $1M in annual revenue.
- Built abuse controls for L7 login flooding and payment fraud using login queueing, IP/ASN reputation, proxy/VPN detection, and threat intelligence, enabling launch without downtime.
- Automated production deployments with Docker and Ansible across AWS & OVH dedicated servers; implemented secrets handling, backups, reverse proxies, and WAF controls.
blogs
... coming soon ...
contact
schedule a call
openloading scheduler…open in calendly
