Web Application Testing
Authentication, authorization, business logic, input handling, session security and server-side attack surfaces.
OFFENSIVE SECURITY · PENETRATION TESTER
Cybersecurity professional with hands-on experience in penetration testing, security engineering and vulnerability research across web applications, APIs, mobile applications, networks, Active Directory and IT/OT environments.
PROFILE
My background combines penetration testing and vulnerability research with hands-on security engineering. I assess systems from an attacker’s perspective while keeping remediation, operational risk and business impact in view.
My experience spans product security research, client-facing penetration testing and consulting, and enterprise security engineering across both IT and OT environments.
PENETRATION TESTING SERVICES
Manual and tool-assisted assessments tailored to the target, attack surface and rules of engagement. Click a service to see the testing scope and deliverables.
Authentication, authorization, business logic, input handling, session security and server-side attack surfaces.
REST and GraphQL security testing focused on authorization, authentication, injection and business logic abuse.
Internet-facing infrastructure, exposed services, remote-access surfaces and externally exploitable configuration weaknesses.
Internal networks, Active Directory, privilege escalation, segmentation and lateral movement attack paths.
Android and iOS application security across local storage, authentication, traffic, APIs and client-side assumptions.
AVAILABILITY
WORK WITH ME
I’m open to freelance, contract and part-time opportunities in offensive security, penetration testing, vulnerability research and security engineering — from focused short-term work to ongoing collaboration.
Project-based security assessments, research, technical reviews and specialized offensive security work.
Fixed-term or ongoing contract support for security teams, consulting companies and technical projects.
Part-time offensive security, application security or security engineering support where ongoing expertise is needed.
CURRICULUM VITAE
Cybersecurity roles spanning product security research, penetration testing, consulting and enterprise security engineering.
SECURITY RESEARCH
Responsible disclosure work recognized by major technology vendors, alongside multiple public CVE records.
CREDENTIALS
Certified API Security AnalystAPIsec University
Practical Network Penetration TesterTCM Security
Certified AppSec PentesterThe SecOps Group
Certified AppSec PractitionerThe SecOps Group
PMPATCM Security
Offensive Web, Mobile, API, Network, Active Directory
Operations SIEM, EDR, Firewalls, Incident Response
Tools Burp Suite, Nmap, Nessus, Metasploit, SQLmap
Automation Python, Go
Frameworks OWASP Top 10, MITRE ATT&CK
CONTACT
Send a short description of what you need, the scope or role, and your preferred timeframe. I’ll have the context needed to continue the conversation.