About

Toul

I’m Toul (pronounced “to-ewl”). I build software in Go and spend most of my time making sure it’s secure.

Now: Staff AI Security Engineer at Cohere

Since May 2026 I’ve been a Staff AI Security Engineer at Cohere, working remotely from New York. The work covers the whole AI stack:

  • AI gateways and guardrails. Enterprise AI gateways and real-time inference guardrails that enforce zero-trust access, DLP, prompt policy and token-level threat mitigation across multi-model deployments.
  • Model security and fuzzing. CoPen, an LLM DAST and automated penetration-testing framework that fuzzes models for prompt injection, jailbreaks and data poisoning before release, plus HiddenLayer and data-scanning pipelines that catch payload injections, dataset corruption and compromised model weights before production.
  • AI supply chain. Automated AI Bill of Materials (AIBOM) and SBOM generation across every model, dataset and container, for full supply-chain visibility and compliance with FedRAMP and the NIST AI Risk Management Framework.
  • Shift-left AppSec. CoCleaner, an internal ASPM platform that brings SAST, DAST, SCA and container scanning together and enforces automated release-readiness gates without getting in developers’ way.
  • Secure AI-assisted development. VS Code and Cursor plugins, and enterprise security policy turned into IDE configuration (.cursorrules), so AI-assisted teams are secure by default.
  • AI governance. “Death to Metrics,” a Model Context Protocol (MCP) server that lets leadership ask about live vulnerability telemetry in plain language, and executive briefings that turn AI/ML risk into strategy and engineering work.

Before

I came to software the long way round: a double degree in Geophysics and Computer Science at the University of Houston, an internship at HP, then a DevOps engineering job there. From there I moved into DevSecOps, building security features for a cloud platform on AWS with Python, Go and Kubernetes, and picked up the AWS Security Specialty and the CISSP along the way.

On the side

I write about application security at AskAppSec, wrote the free beginner’s book Automate the Boring Stuff with GO, and run Krabber, a small social network built to stay cheap and secure.

This site collects my projects and my writing from over the years.