The Story of Zak

I'm Zak. I've spent twenty-plus years building systems that guard things that are never allowed to break — including the Coinbase cold storage that, in its day, held around a tenth of the entire crypto market. Now I run invariant, where I design and build things to be secure instead of auditing them after the fact. Let me help you build something that holds.

Want the short version instead? →

I am the hacker child of hacker parents. I grew up at a command line: my mom teaching me shell, my dad hex-editing my and my sisters' names into the video games we played together. Mom worked IT at the local university, so summers in fourth and fifth grade were spent on her campus's terminals and Solaris workstations. Fifth grade also produced my first exploit. I figured out that our typing games only started the clock at the first keystroke and paused it whenever a menu opened, so I weaponized hunt-and-peck and cheated my way to the highest WPM score in the school. By sixth grade I'd gotten into my first computer trouble: the library's overdue-book database was just sitting on a shared network drive, and my return dates were suspiciously negotiable. I got caught. My sentence was to become the school's first-line tech support, which turned out to be my first job in defense. High school escalated things: exploiting bank reward programs, online shopping platforms, and a brisk sideline in getting classmates around the school's IT and firewall systems. The rewards attack was one I'd later learn had a name, TOCTTOU (time-of-check to time-of-use), but at the time it just felt like the business logic wasn't paying attention.

The curiosity never went away; eventually someone would pay me to point it in the right direction. But first, I went legit by degrees: an honors BSc in computer science with a networking and security specialty, plus two master's, one in digital privacy & network security and one in security & applied cryptography. History repeated early in undergrad, when the CS department made me first-line support again, hiring me from my second semester as the catch-all TA. A question from anyone in any course came to me first. The first master's happened during a junior year abroad in Sweden, before the BSc was done; even my transcript has out-of-order execution. Grad school put me on the DEF CON stage with original attack research: "Transcending Cloud Limitations by Obtaining Inner Piece," using file fragmentation and tombstoning to store unlimited data in Dropbox's free tier. The same family of business-logic flaws I'd been finding since high school, now with an audience.

Then I went corporate: payments security at Amazon, building bank partner integrations on ISO 20022 rails, where a malformed message isn't just a bug, it's transactions that no longer reconcile. From there, LinkedIn's trust engineering team. Internal security tooling, PKI, and the vendor reviews that keep a platform of half a billion identities honest. At Fitbit I switched sides of the data, designing anonymity and security features so the most intimate dataset people generate (their own heartbeat) stayed theirs.

Next was Coinbase, in 2017, as the first engineer hired to the security team. The pitch I made to my future boss: what the team needed was an engineer who knows security, not a security engineer. I grew to Senior Staff there. I built version 4 of the cold storage system, provided initial architecture oversight for what became Coinbase Custody, and led key generation operations: the ceremonies where a mistake is measured in billions. For scale, the vault v4 replaced was one Coinbase publicly described as holding about 10% of all bitcoin in circulation, and during v4's tenure Messari put roughly 11% of the entire crypto market cap in Coinbase's custody. That work made me a co-inventor on two patents and earned a writeup in Wired.

My final chapter there was a preview of invariant: an in-house consulting architect and advisor for internal products, which is how I came to design the data-sharing mechanisms Coinbase used with external partners (a third patent) and to oversee hot wallet architecture.

Since then I've been the security person founders call early. At Skiff, as Director of Security and a founding engineer, I designed the cryptographic primitives and libraries the product stood on and laid out the initial backend architecture for Skiff Mail; the company was later acquired by Notion. My favorite part of the role, though, was the mentorship: helping junior engineers see security as a quality of the product, not a feature, and definitely not a roadblock. After that came security architecture lead at c= (a Block subdivision) and staff security engineer at Postman. Different products, same job: make the guarantees hold.

Along the way I've stayed a practitioner in public: a keynote at Blockchain McGill, a couple of years helping organize BSides SF, and security fixes contributed upstream to sudo and OpenSSL, software that runs on more or less everything.

That school library is nearly thirty years behind me now, and the last twenty-plus have been spent professionally guarding the things that are never allowed to break: payments, identities, private keys, and other people's secrets. Eventually I named a company after the idea.

Now I run invariant, a security consulting practice out of the Cayman Islands. It exists because of a pattern I kept hitting as an in-house leader: companies were quick to hire me for direction, and slow to give me the mandate or resources to build it. Architectures got approved and never staffed; processes everyone agreed needed changing went unchanged. Stagnation, frustration, repeat.

Most security contracting firms will play appsec goalkeeper or auditor for you, reviewing what you've already built and cataloguing what's wrong with it. invariant works upstream of that: design and direction. I build things to be secure rather than securing things other people built. Architecture decisions, security strategy, the shape of the system before the mistakes get expensive. And when the plan is set, I don't hand over recommendations and leave. I stay to build.

The name is the pitch: an invariant is the property of a system that must remain true no matter what the system does. Finding yours, and making sure it survives contact with reality, is the work.

Highlights

Career arc

  • 20+ years in security architecture and operations, from FAANG scale to first-hire startup chaos.
  • Progression: builder → architect → security leader → founder-advisor.

Coinbase (first engineer on the security team → Senior Staff)

Leadership & founding roles

  • Director of Security & founding engineer, Skiff — acquired by Notion. Cryptographic primitive & library design; initial backend architecture for Skiff Mail; mentored junior engineers on security as a product quality, not a feature or roadblock.
  • Security architecture lead, c= (Block subdivision).
  • Staff security engineer, Postman.

Big-company foundations

  • Amazon payments security: ISO 20022 / CAMT.053 bank partner integrations.
  • LinkedIn trust engineering: internal security tooling, PKI, vendor security reviews.
  • Fitbit: user data anonymity and security features.

Research, speaking & community

  • Presented original attack research at DEF CON: "Transcending Cloud Limitations by Obtaining Inner Piece" — file fragmentation & tombstoning to bypass Dropbox free-tier storage limits.
  • Keynote speaker, Blockchain McGill conference.
  • Organizer, BSides SF (multiple years).
  • Upstream security fixes to sudo and OpenSSL.

Education

  • Honors BSc, Computer Science (networking & security specialization) — University of Windsor.
  • MSc, Digital Privacy & Network Security — Karlstad University (School of Economics & Technology), Sweden.
  • MMath, Security & Applied Cryptography — University of Waterloo.

Executive summary

  • Upstream of the auditors: design and direction, not just goalkeeping — then stays to build.
  • Custody-grade thinking: has secured assets where failure is irreversible.
  • Full-spectrum: payments rails, PKI, privacy engineering, crypto custody, API platforms.
  • Founder-fluent: knows what an early security hire actually signs up for; has been one.