About

Grayscale and dithered picture of Andrew

I’m a Principal Engineer at MITRE working on software security, vulnerability management, and open source. I lead Hipcheck, which helps maintainers and users assess dependency supply-chain risk via plugin-based analyses.

I also work on the CVE system, improving authz / authn, introducing support for Package URLs in CVE Records, and enhancing the processes of the Quality Working Group.

I previously served on the OmniBOR Core Team, including leading creation of the Rust library and omnibor CLI.

WorkRésumé PDF

I want the people who build and maintain software to be able to make informed decisions about what they depend on. That is why I founded Hipcheck and led its redesign as an extensible supply-chain analysis tool.

I am drawn to work at the intersection of technical standards, public policy, and open source communities. I have advised federal software policy on SBOMs and open source security, and through OmniBOR, I worked on better ways to handle software identity.

Memory safety matters to me because it makes software safer by default. In “Memory Safety for Skeptics”, published in ACM Queue and Communications of the ACM, I make the case for pursuing it amid competing priorities. I have taught Rust at MITRE and programming language theory at CSUSB, spoken at RustConf and Rust Belt Rust, contributed to the official Rust documentation and Rustonomicon, and edited a book on Rust procedural macros.

Talks

Social / Contact

@alilleybrinker.com

Follow Andrew’s writing and conversations on Bluesky.

Loading Bluesky profile.

@alilleybrinker

Explore Andrew’s open-source software and projects on GitHub.

Loading GitHub profile.

Message me on Bluesky for my Signal username to chat.

You can also find me on Mastodon, LinkedIn, Hacker News, Lobste.rs, and Reddit.

AI Policy

The words on this site were written by Andrew with care. Its design was implemented with the aid of AI. If AI-generated content is ever posted, it will be clearly identified.