Application security
Secure API design, auth boundaries, tenant isolation, input validation, and threat-led review.
[ SECURITY / PROOF INDEX ]
AVAILABLE FOR SECURITY ROLES
I work across application security, offensive testing, and secure product engineering. Because I also build full-stack systems, I approach security from both sides: how software is assembled and how its boundaries fail.
Three working areas. Details live with their evidence, not repeated here.
Secure API design, auth boundaries, tenant isolation, input validation, and threat-led review.
Web and API assessment, attack-surface analysis, vulnerability validation, and pentest workflows.
Security controls built into full-stack products, cloud deployments, and AI-assisted systems.
Role context and published writing. Full histories stay on their own pages.
Built and secured an autonomous AI pentesting SaaS platform for MSPs and enterprises, focusing on secure APIs, auth/authz, tenant isolation, RLS, and compliant architecture.
Architected and built a PTaaS and ASM platform with security testing modules, attack-surface workflows, XSS detection automation, cloud deployment, and technical documentation.
Working capabilities grouped by security function and engineering context.
Active training paths and lab work. Status reflects ongoing study, not completed credentials.
Hack The Box
TryHackMe
TryHackMe
Self-study and labs
[ NEXT OPERATION ]