About
One architect, not an agency roster.
You get the person you spoke to in the first conversation. Nobody gets swapped for a junior after the contract is signed, because there is nobody to swap in.
I work with engineering teams on the part of AI systems that is not the model: how context gets assembled, how retrieval behaves on queries nobody anticipated, how you know whether a change helped, and what the whole thing costs per request at scale.
The pattern I see most often is a team that built something genuinely impressive in a few weeks, demoed it to real enthusiasm, and then spent six months discovering that the distance between a good demo and a dependable product is mostly architecture. Retrieval that was fine on twenty test questions degrades on twenty thousand real ones. An agent that handled the expected path has no defined behaviour for the unexpected one. Nobody can say whether last week’s prompt change was an improvement, because nothing measures it.
None of that is a failure of engineering talent. It is a failure of having someone whose job is the system as a whole — the boundaries, the failure modes, the feedback loops — while everyone else is correctly focused on shipping features. That is the role I play, for as long as a team needs it and no longer.
My day work is AI architecture inside a security company, which has shaped how I look at these systems. Once a model handles untrusted input, prompt injection and data exfiltration through model context stop being theoretical and become ordinary design constraints — the same category of concern as authentication or input validation. Most teams reach that realisation later than they would like to.
I work independently and stay that way deliberately. No vendor partnerships, no reseller margins, no referral arrangements. When I tell you a particular model or database is the right call, there is no second reason behind it.
Areas of depth
- LLM security & prompt injection
- Retrieval & vector search
- Agent orchestration
- Evaluation & observability
- Prompt & context engineering
- Inference cost modelling
- Distributed systems
- Platform & DX
Background
Where this comes from.
-
Principal Software Architect, CyberArk — Data & AI Office
Architecture for AI systems inside a security company, with a focus on LLM security: prompt injection, data exfiltration through model context, and the failure modes that only appear once a model is handling untrusted input.
-
Principal Software Architect, Soluto (Asurion)
Front-end and back-end architecture at scale. Built and maintained a shared component library with visual-regression and accessibility testing, and drove tooling that standardised how new services were generated and deployed.
-
Engineering roles, Verizon Media & Hewlett Packard Enterprise
Web and platform engineering in large distributed organisations — the environments where architectural decisions have to survive many teams and a long time horizon.
-
Technology journalist, TheMarker
Writing about technology for a general audience. Useful practice for the part of this job that is explaining a hard system to people who do not have your context.
-
Author and lecturer
Six programming books in Hebrew — JavaScript, Node.js, React, and MySQL — plus lecturing at Ono Academic College and the University of Haifa, and long-running technical writing at internet-israel.com.
Next step
Want to know if I am the right fit?
The fastest way to find out is forty-five minutes on a call. Bring the problem, not a brief.