AI Security & Governance

Joao Coelho

Security Engineer & Product Manager — AI SecurityI work on the security problems at the frontier of the industry rather than rehearsing outdated playbooks. My research focuses on practical Agentic AI security controls that teams can actually implement. Currently finishing my master's and building in the open.

Selected Work

September 2026

trifecta — AI agent security rubric

An AI agent that can read private data, ingest attacker-influenced content, and communicate externally is exploitable end-to-end by a single prompt injection. The rule is widely cited and rarely enforced. Trifecta is a versioned rubric for auditing agent tool permissions against it, with a pinned test corpus and a published defect register.

MAY 2026

NIST AI RMF → Agent Controls Mapping

A control reference for tool-using LLM agents and MCP-based deployments. The NIST AI RMF tells you the outcome to aim for — it doesn't tell you the control. This document pairs all 72 subcategories with concrete controls for AI agents that act in production, plus the evidence a security reviewer will actually ask for.

All four functions · 72 subcategories · CC BY 4.0

June 2026

Threat Model: Tool-Using LLM Agent

A STRIDE threat model for a reference tool-using / MCP-based agent. Nineteen enumerated threats — across spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege — each with a primary mitigation and a worked residual-risk score. Every threat is traced to the NIST AI RMF, the SANS Critical AI Security Guidelines v1.4, and the OWASP Top 10 for Agentic Applications, and anchored to real 2025 incidents (EchoLeak, the GitHub MCP exploit, Gemini memory poisoning, the Replit production-DB deletion).

STRIDE · 19 threats · NIST / SANS / OWASP-mapped · CC BY 4.0

Writing

Articles forthcoming as I publish through my master's program — follow on LinkedIn

about

I'm a security engineer working on AI governance and GRC. My work sits between the policy layer — NIST AI RMF, ISO/IEC 42001, the EU AI Act, SOC 2, CAIQ — and the engineering layer where AI agents actually run.The gap between the two is the interesting part, and it's where the old playbooks stop being useful: frameworks rarely say what a control looks like when an agent can call tools, reach MCP servers, and act in production. My work is figuring out what those controls are and whether they hold up once an agent is live.If you're working on the same problems I'd like to hear from you.CISSP candidate, PMP holder. Based in Reston, VA. Currently Senior Associate, Security Engineering and Management at AIG.

Contact

Email: [email protected]
LinkedIn: https://www.linkedin.com/in/joaocoelho1/
For research collaborations, speaking, or advisory inquiries: get in touch by email.

© 2026 Joao Coelho. Personal site — views are my own.