Application Security Engineer @ SproutXP
Finding the bug in review, not in production.
- π‘οΈ Application Security Engineer at SproutXP, embedded with product teams to build security into the SDLC.
- π I spend my days on secure code review, web & API penetration testing, threat modeling, and vulnerability triage.
- π€ Big believer in security automation β SAST, DAST, and dependency scanning wired straight into CI/CD.
- π Always learning: OWASP Top 10 deep dives, exploit primitives in modern frameworks, and supply chain security.
- π¬ Ask me about AppSec, secure code review, DevSecOps, or shifting security left.
Languages
Security
Cloud & Infra
| Area | Focus |
|---|---|
| π§ͺ Secure Code Review | Manual review + SAST tuning to cut false positives |
| π΅οΈ App Pentesting | Web and API testing against the OWASP Top 10 |
| π§΅ Threat Modeling | Design reviews, abuse cases, STRIDE on new features |
| π¦ Supply Chain | Dependency risk, SBOMs, and third-party library triage |
| βοΈ DevSecOps | Security gates in CI/CD without slowing shipping |
"Every input is hostile until proven otherwise."