I'm an application security engineer with a passion for diving deep into the inner workings of software and hardware. My expertise spans from low-level programming to modern DevSecOps practices.
I'm deeply passionate about low-level programming and web application security. There's something incredibly satisfying about understanding how systems work at their core, whether it's:
- Writing and optimizing kernel drivers
- Exploring OS internals and memory management
- Reverse engineering binaries and protocols
- Writing secure, scalable and reliable microservices and web applications while also following OWASP
Application security is at the heart of what I do, spanning both traditional on-premises environments and modern cloud infrastructures. My security approach includes:
- Comprehensive penetration testing to identify vulnerabilities before they can be exploited
- Secure coding practices and vulnerability assessments
- Runtime protection mechanisms and security architecture design
I believe security must be integrated throughout the development lifecycle, not bolted on at the end. My approach to DevSecOps includes:
- Implementing automated security testing in CI/CD pipelines
- Infrastructure as Code (IaC), Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA) security scanning
- Container and VM security hardening
- Malicious Memory Scanner
- Vulnerable Kernel Driver Finder
- Containerized and Stateless AES File Encrypt/Decrypt Web Application
- Software Licensing Management System
- Page Table Injector