Services / Working with me

Understand the risk.
Know what to fix.

Direct technical collaboration for teams that need a careful assessment, a code review, or a better security workflow.

/01

Web & API penetration testing

Manual assessment of application behavior, with particular attention to authentication, authorization, session handling, and business logic. Scope is agreed around your application, users, and environment.

What the engagement covers
  • Scoping and agreed testing boundaries
  • Web application and API testing
  • Findings with evidence, context, and impact
  • Prioritized remediation guidance
  • Technical walkthrough and agreed retesting
/02

Secure code review & SAST triage

Reviewing findings against the implementation so engineering teams can distinguish actionable issues from noise and understand what needs to change.

Where I can contribute
  • Manual source review in the agreed scope
  • Fortify and other SAST/SCA result triage
  • Context and evidence for finding validation
  • Developer-focused remediation discussions
  • Review automation where the task is repeatable
/03

Network & identity security

Internal and external assessments connecting exposed services, access boundaries, and configuration to the risks in your environment.

Potential scope
  • Internal and external network assessments
  • Active Directory security reviews
  • Service and access-control configuration
  • Evidence-supported findings and priorities
  • Remediation guidance and technical handover
/04

Security automation & AI systems

Custom tooling and engineering support for assessment, review, and reporting. My experience includes Python pipelines, JavaScript analysis, and the evaluation of LLM-assisted security systems.

Potential scope
  • Assessment and reporting utilities
  • Repeatable SAST triage workflows
  • CI/CD security and vulnerability tracking
  • Evidence handling and evaluation design
  • Implementation, documentation, and handover
The engagement

One conversation at a time.

Let’s talk about your security.

Tell me what you’re building and what you need assessed.

Discuss your project