Penetration Tester and Security Engineer specializing in Application Security, Network Security, and DevSecOps. I conduct vulnerability assessments and penetration testing across web applications and network infrastructure (Nmap, DNS enumeration, zone transfers, Burp Suite, SQLMap), perform secure code review and static analysis (Semgrep, SonarQube), and architect security-first infrastructure with detection engineering (IDS/IPS, SIEM, honeypot deployment) and server hardening.
I bring a builder's perspective to security work โ hands-on experience architecting production-grade microservices and distributed systems in Go gives me a deep understanding of both offensive and defensive security, from exploiting real vulnerabilities to designing the systems that prevent them. This includes secure API design, secure SDLC practices, network security best practices, and integrating ML/Computer Vision systems with security considerations.
Currently focused on offensive security (VAPT, network reconnaissance, exploitation, threat detection), defensive security and detection engineering (Wazuh SIEM, Snort IDS, honeypot analysis), malware analysis, server hardening, and secure backend/infrastructure architecture. Pursuing eLearnSecurity Junior Penetration Tester (eJPT) certification, with OSCP as the next target.


