Portrait of Tevin

Maryland • Security & Compliance Engineer

Building AI-powered tools that make federal compliance move at developer speed.

I design DevSecOps tooling that turns NIST, OSCAL, and FedRAMP-heavy workflows into practical systems engineers can ship with.

  • Python
  • TypeScript
  • Node.js
  • OSCAL
  • NIST 800-53
  • FedRAMP
  • Docker
  • AWS
  • GitHub Copilot

Flagship Product

OSCAL Pocket Guide

A mobile reference for compliance engineers, security practitioners, and builders working with OSCAL, NIST guidance, and FedRAMP documentation.

The goal is simple: make the source material easier to navigate from anywhere so teams can move faster without losing the compliance thread.

Why it matters

  • Quickly locate the publications behind OSCAL-based work
  • Keep reference material usable outside the desktop workflow
  • Support builders and assessors working in federal environments

Current Projects

Security, compliance, and AI systems built for real operators

Cybersecurity-LLM-Engineering

Evidence-backed portfolio project for LoRA fine-tuning, dataset-quality analysis, and authorization-evidence workflows for an on-prem cybersecurity LLM.

Open project

IV-Code-Defender

Claude Code skills plus a sandboxed agent pipeline for finding, verifying, patching, and exporting vulnerability findings as OSCAL evidence.

Open project

ThreatCanvas

AI-powered STRIDE threat modeling with interactive attack surface visualization.

Open project

OSCALFlow

GitHub CLI extension that scans repos, auto-detects NIST 800-53 control implementations, and generates FedRAMP-ready OSCAL SSPs with AI-powered validation.

Open project

TRACE

Multimodal AI compliance automation that maps evidence to NIST 800-53 and generates OSCAL artifacts using Gemini 3 Pro.

Open project

SYSAdmin-CoPilot

Agent-native infrastructure management control plane with secure tool gateways.

Open project

COMPASS

Voice-first FedRAMP agent using Gemini Live for real-time NIST 800-53 control mapping, gap analysis, and OSCAL document generation.

Open project

B.O.B.B.I.E

Hierarchical multi-agent federal compliance assessment engine powered by AWS Bedrock (Amazon Nova) with evidence-driven findings and POA&M output.

Open project

What I'm Building

Three themes shape the portfolio

Automating compliance

Turning NIST 800-53, OSCAL, and FedRAMP requirements into developer-friendly tooling.

AI + security

Using Copilot, RAG pipelines, and LLM systems to connect policy with code.

Open-source DevSecOps

Making federal-grade security workflows more accessible through automation and CLIs.

Highlights

Work grounded in standards, open source, and practical delivery

NIST RFC discussion

Started an OSCAL discussion with NIST around a new reference taxonomy model.

Read discussion

Hackathon build

Built OSCALFlow for the GitHub + MCP Hackathon as a native CLI for valid OSCAL 1.2.0 JSON.

View OSCALFlow

Detection scale

OSCALFlow detects 50+ control implementations across 8 languages with AI-powered validation.

See details

GitHub Activity

GitHub contribution graph for ivproduced

Connect

Say hello or follow the work