Tate McCauley

Hey, I'm Tate.

I'm a Forward Deployed Engineer at Paramify, where I build tools that automate the tedious parts of FedRAMP and GRC — collecting security evidence, validating controls, and turning compliance work into code.

My path into tech didn't start by discovering a 0-day or breaking into a computer. It started small: figuring out how to code simple programs on a TI-84 calculator back in junior high. I was hooked and kept learning about computers until I landed in the world of cybersecurity and IT. I graduated from BYU in Cybersecurity in the spring of 2026.

Seeing Security from Both Sides

I’ve had a couple of internships that gave me a look at security from two totally different angles.

At FJ Management, I was thrown right into the deep end as an ITGC auditor. I got to help with the security audit for Maverik's acquisition of Kum & Go and took a close look at their software development pipelines. I learned to think about security from 10,000 feet up — strategy, risk, and compliance.

But I knew I also wanted to see what day to day life in security looked like.

That's why I spent the following months at Big West Oil, living on the front lines of security ops. I was the one triaging threats in our XDR, watching the network for trouble in Darktrace, and managing the vulnerabilities we found from our own pen tests.

Having both perspectives taught me one thing: you can't write good policy if you don't know the tech, and you can't protect the tech if you don't know the business risk.

From Auditing Security to Building For It

Those internships taught me to see security from both sides. At Paramify, I get to act on both. As a Forward Deployed Engineer, I build tools — more and more of them AI-native — that take the manual, spreadsheet-heavy reality of compliance and turn it into something automated. It turns out the "boring" corner of security I first met as an auditor is quietly becoming one of the most interesting places to build.

Why This Blog?

For one, I want to share what I'm learning as compliance shifts from checklists to code — especially now, with FedRAMP 20x rewriting the rules and AI changing how we build.

For another, I want to become a better writer. After spending most of my life avoiding opportunities to write down my thoughts, I figured I'd just dive right in.

Beyond the Keyboard

When I'm not staring at a screen, I'm usually outside. Lately that means hiking and cycling around Utah. Otherwise, you can find me playing guitar.

Thanks for stopping by. Feel free to connect with me on LinkedIn or check out what I'm writing about.