About

I’m Toul (pronounced “to-ewl”). I build software in Go and spend most of my time making sure it’s secure.
Now: Staff AI Security Engineer at Cohere
Since May 2026 I’ve been a Staff AI Security Engineer at Cohere, working remotely from New York. The work covers the whole AI stack:
- AI gateways and guardrails. Enterprise AI gateways and real-time inference guardrails that enforce zero-trust access, DLP, prompt policy and token-level threat mitigation across multi-model deployments.
- Model security and fuzzing. CoPen, an LLM DAST and automated penetration-testing framework that fuzzes models for prompt injection, jailbreaks and data poisoning before release, plus HiddenLayer and data-scanning pipelines that catch payload injections, dataset corruption and compromised model weights before production.
- AI supply chain. Automated AI Bill of Materials (AIBOM) and SBOM generation across every model, dataset and container, for full supply-chain visibility and compliance with FedRAMP and the NIST AI Risk Management Framework.
- Shift-left AppSec. CoCleaner, an internal ASPM platform that brings SAST, DAST, SCA and container scanning together and enforces automated release-readiness gates without getting in developers’ way.
- Secure AI-assisted development. VS Code and Cursor plugins, and enterprise security policy turned into IDE
configuration (
.cursorrules), so AI-assisted teams are secure by default. - AI governance. “Death to Metrics,” a Model Context Protocol (MCP) server that lets leadership ask about live vulnerability telemetry in plain language, and executive briefings that turn AI/ML risk into strategy and engineering work.
Before
I came to software the long way round: a double degree in Geophysics and Computer Science at the University of Houston, an internship at HP, then a DevOps engineering job there. From there I moved into DevSecOps, building security features for a cloud platform on AWS with Python, Go and Kubernetes, and picked up the AWS Security Specialty and the CISSP along the way.
On the side
I write about application security at AskAppSec, wrote the free beginner’s book Automate the Boring Stuff with GO, and run Krabber, a small social network built to stay cheap and secure.
This site collects my projects and my writing from over the years.