>> INITIATING SEQUENCE

SECURING
THE UNKNOWN

I break things to understand how they work, and I build things to ensure they can't be broken. Specializing in vulnerability management, penetration testing, and secure architecture design.

EXPLORE

>> CORE COMPETENCIES

Web Application Security API Security Penetration Testing Vulnerability Management Threat Modeling Secure SDLC Source Code Analysis Mobile App Security Active Directory Security
01

EXPERIENCE

08/2024 — PRESENT STRIX CYBER SECURITY

Security Engineer

  • Conducting advanced Web Application, API, and Mobile security assessments, focusing on identifying OWASP Top 10 vulnerabilities and logical flaws.
  • Performing code reviews to validate remediation efforts, ensuring vulnerabilities are effectively patched at the source code level.
  • Collaborating with development teams to provide remediation guidance and promote secure coding best practices throughout the Software Development Lifecycle.
  • Executing threat modeling sessions to analyze potential risks and design secure architectures for new features.
  • Developing custom scripts and tools to automate security testing processes and enhance vulnerability detection capabilities.
Web App Sec API Security Mobile App Sec OWASP Top 10 Code Review Threat Modeling Python
12/2025 — 02/2026 VRISTOPAY

Vulnerability Management & Security Engineer

  • Established a risk-based lifecycle using CVSS v3.1 and NIST SP 800-40 standards to prioritize mission-critical financial assets.
  • Implemented a "Verify-Before-Trust" model for third-party libraries using SCA and SBOM (CycloneDX) management.
  • Integrated SAST/DAST security gates into the SDLC and architected incident response workflows based on the FIRST PSIRT framework.
Vuln Management SAST/DAST SCA/SBOM PSIRT NIST SP 800-40 CycloneDX
06/2023 — 07/2024 TUV AUSTRIA SYBERCODE

Jr. Security Engineer

  • Executed penetration testing and application security testing within the Secure Software Development Lifecycle.
  • Gained significant experience in the Purple Team approach, collaborating on Managed Detection and Response (MDR) services to improve defense mechanisms.
  • Assisted in vulnerability management processes and enterprise remediation efforts.
Penetration Testing AppSec Testing Purple Team MDR Enterprise Remediation
04/2023 — 06/2023 STRIX CYBER SECURITY

Jr. Security Engineer

  • Conducted comprehensive penetration testing and application security assessments.
  • Executed API testing and web penetration tests while ensuring security best practices were followed in development.
  • Contributed to the identification and reporting of critical security vulnerabilities.
Web Pen Testing API Testing Vulnerability Reporting
01/2023 — 04/2023 STRIX CYBER SECURITY

Application Security Intern

  • Enhanced skills in identifying vulnerabilities and performing code review.
  • Learned and applied secure coding practices while contributing to team projects.
Application Security Code Review Secure Coding
02

BLOG POSTS

03

PROJECTS

04

CERTIFICATIONS

Web Application Penetration Tester eXtreme

INE
eWPTX
2025