I'm an application security engineer & pen tester specializing in web and mobile application security, with over 12 years of software engineering experience across .NET and full-stack development. My journey into security started as a developer, where I saw firsthand how disconnected security testing can feel without real guidance. That frustration turned into curiosity, and eventually a career focused entirely on breaking and securing applications. These days I help developer teams build security into their SDLC, perform application pentests, hunt bugs, and tackle CTF challenges. This blog is where I document CTF writeups, exam reviews, and the techniques and tools I find useful.
Present
Helping developer teams secure their SDLC, performing application pentests, hunting bugs, and tackling CTF challenges.
12+ years
Full-stack and .NET development experience that informs how I approach breaking and securing applications.
Always open to connecting with people interested in application security or building secure software. Find me on GitHub .