I am a backend-focused developer with a Bachelor of Information Technology and Computing (First-Class Honors), building backend systems with Java, Spring Boot, Spring Security, REST APIs, Hibernate/JPA, and PostgreSQL.
I am currently expanding from backend development into application security and penetration testing, with a focus on understanding how web applications and APIs are designed, attacked, secured, and tested.
- Web Application Security
- REST API Security
- Authentication & Authorization
- OWASP Top 10
- Vulnerability Assessment & Penetration Testing
- Secure Backend Development
- Linux & Networking Fundamentals
- Security Testing and Reporting
Backend: Java · Spring Boot · Spring Security · Hibernate/JPA · REST APIs
Databases: PostgreSQL · SQL
Security: Burp Suite · Nmap · HTTP/HTTPS · OWASP methodology
Development: Git · GitHub · Maven · Docker
Projects are being developed as part of my transition into application security and penetration testing.
- Vulnerable Spring Boot Lab — deliberately vulnerable web/API application used to study, reproduce, document, and remediate common security vulnerabilities.
- Security Learning — structured notes, practical labs, methodology, and security research.
- Penetration Testing Reports — sanitized assessment reports demonstrating methodology, findings, evidence, impact, remediation, and retesting.
- Security Tools — small utilities and automation scripts developed for authorized security testing and learning.
Web & API Fundamentals
↓
OWASP Top 10
↓
Burp Suite & Manual Testing
↓
API Security
↓
Vulnerability Assessment & Reporting
↓
Linux / Windows / Active Directory
↓
Real-world Authorized Security Testing
My goal is to develop into a junior penetration tester / application security professional, combining my backend engineering experience with practical offensive security skills.
I believe understanding how software is built makes it easier to understand how it can fail — and how it can be secured.
All security testing documented here is performed against systems I own, intentionally vulnerable applications, labs, or targets for which I have explicit authorization.
- GitHub: @edrine23
- LinkedIn: www.linkedin.com/in/idipoedrine
Learning in public. Building, breaking, fixing, and documenting.


