About
security architect by day, bug bounty hunter by night — i break things to understand how to defend them better.
i handle platform and AI security at one of the largest pharma companies. outside work, i spend my time hunting vulnerabilities, writing security tools, and documenting everything i learn on this blog.
the thing that keeps me going is curiosity — there’s nothing quite like finding the flaw that nobody else noticed.
what i do
offense — bug bounty · web & api pentesting · cloud security (aws, azure, gcp) · vulnerability research
defense — platform & ai security · soc operations · siem & edr · devsecops · incident response
build — security tooling · automation · open source contributions · this blog
certifications
| Cert | Full Name | Issuer |
|---|---|---|
| BCP | Burp Certified Practitioner | PortSwigger |
| CDP | Certified DevSecOps Professional | Practical DevSecOps |
| eWPTx | Web App Pentester eXtreme | INE Security |
| eWPT | Web App Penetration Tester | INE Security |
| eCPPTv2 | Certified Penetration Tester eXtreme | INE Security |
| CCSK | Cloud Security Knowledge v4 | CSA |
this blog
i write to think. bug bounty writeups, cloud security research, CTF solutions, SOC learning notes — whatever i’m into that week ends up here.
mostly for future-me, so i don’t relearn things twice. if it helps you too, that’s a bonus.