Security engineer with an offensive background and a builder's mindset.
I break web apps, APIs, and mobile clients β then automate the boring parts so findings get caught faster and fixed for good.
|
|
"Find the pattern. Automate the detection. Scale the fix."
HTTP/2 DNS TCP/IP TLS OAuth 2.0 / OIDC SAML JWT OWASP Top 10 CIS Benchmarks STRIDE
|
Building:
- burp-sec-skills β Pentest automation skills for Claude Code
- semgrep-security-rules β CI/CD SAST rules from real findings
- api-threat-model β OpenAPI β Threat Model CLI
Learning:
- AWS Security Architecture & hardening patterns
- AI Agent security & MCP trust boundaries
- Detection engineering at scale
- Kubernetes & container security