Selected work / Assessments, engineering & research

From finding the issue
to improving the system.

My work spans hands-on assessments, engineering collaboration, custom tooling, and security research. These overviews describe my responsibilities without exposing client or employer details.

01 / Application security

Enterprise application assessments

Web & APIManual testing

Assessing application portfolios for weaknesses in authentication, authorization, and business logic. The work includes investigating relationships between components, validating findings, and working with engineering teams on remediation.

My contribution

Manual penetration testing, secure code review, SAST/SCA triage, supporting evidence, technical reporting, and validation of proposed fixes.

Web & API assessments ↗
02 / Independent consulting

Full-cycle client engagements

ScopingReporting

Running penetration testing engagements for business clients, with responsibility for the work from the initial scope to the findings presentation.

My contribution

Establishing testing boundaries, performing the assessment, documenting impact and evidence, and helping technical and nontechnical stakeholders understand the remediation priorities.

Discuss an engagement ↗
03 / Security automation

Fortify triage pipeline

PythonSASTPrivate tooling

Building a Python pipeline to consolidate recurring Fortify SAST triage work into a repeatable process. The goal is to reduce manual handling of results and make the review more consistent.

My contribution

Workflow design, implementation, findings processing, and integration into the review process. Context and human validation remain part of deciding which results represent real security issues.

Code review & triage ↗
04 / Research & engineering

Agentic security systems

AI securityEvaluationPrivate engineering

Developing and evaluating LLM-assisted assessment systems, alongside the controls and reporting needed to review their work. My responsibilities extend beyond the prototype to deployment, operation, training, and troubleshooting.

My contribution

System design, implementation, testing, findings validation, and evidence-focused reporting. The public LLM handbook explores related design questions through a separate offline reference and a documented historical case study.

The public repository is not a release of a private operational system. Its benchmark limitations are documented in the project.

Explore the public handbook ↗
05 / Vulnerability research

Private enterprise programs

Application behaviorResponsible reporting

Investigating high-impact vulnerabilities in private enterprise programs. This work depends on understanding the application, questioning assumptions, and documenting a clear, supportable finding.

My contribution

Independent research, manual analysis, impact assessment, and reporting. The details of private targets and findings are not part of this public portfolio.

Professional background ↗
06 / DevSecOps

Security in the delivery workflow

CI/CDInfrastructure

Integrating security checks, vulnerability tracking, and centralized logging into engineering workflows, with hands-on work across containerized infrastructure and deployment tooling.

My contribution

Security control integration, infrastructure automation, service configuration, operational troubleshooting, and collaboration with development teams.

Security engineering ↗

Let’s talk about your security.

Tell me what you’re building and what you need assessed.

Discuss your project