Security-Focused Software Engineer focused on AppSec, DevSecOps, secure full-stack development, web and network security testing, security tooling, and applied AI.
I build practical projects related to authentication and session security, web security assessment, network discovery, defensive monitoring, and security-oriented data analysis.
- Application Security (AppSec)
- DevSecOps
- Web and Network Security Testing
- Secure Full-Stack Development
- Network Security
- Security Tooling
- Applied AI for Security
Go, React, and PostgreSQL authentication and session management system for secure stateful authentication, RBAC, session governance, and audit telemetry.
Django REST Framework + React/Vite simulator for API throttling, fixed-window rate limiting, cooldown analysis, and 429 validation.
React + Node/Express passive web security auditor for TLS/SSL posture, HTTP security headers, cookie policies, and SSRF-safe target validation.
ASP.NET Core + React password security tool with zxcvbn scoring, HIBP breach checks, generator validation, and xUnit-tested APIs.
FastAPI + Scikit-Learn + React detection pipeline for SQLi/XSS payload analysis with TF-IDF/Logistic Regression and structured telemetry for SIEM ingestion.
Go-based network asset discovery engine with ARP, SNMP, and mDNS sweeping, offline MAC enrichment, and real-time SSE monitoring.
Read-only PowerShell Windows baseline auditor with Microsoft/CIS-style checks, role-aware profiling, and HTML/JSON/CSV reporting.
Languages: Python, Go, C#, JavaScript, TypeScript, SQL, PowerShell
Backend: Django, FastAPI, ASP.NET Core, Node.js, Express
Frontend: React, Vite
Databases: PostgreSQL, SQLite
Security / DevSecOps: GitHub Actions, Docker, Nginx, Trivy, Gitleaks, OWASP, SIEM workflows
Network / Infrastructure: TCP/IP, TLS, SNMP, ARP, mDNS, Windows, Linux