Senior Application Security Engineer with 5+ years securing enterprise systems across web, mobile, and API platforms. Currently at PwC — building tooling, breaking things (legally), and making software safer.
cat about.txt
I'm a Senior Application Security Engineer specializing in web application penetration testing, iOS/Android mobile security, API assessments, and source code analysis (SCA). With over 5 years across banking, e-commerce, and enterprise environments, I bridge the gap between offensive security findings and practical remediation.
Currently a Senior Associate at PwC, I build internal security automation tooling alongside conducting comprehensive assessments. Previously at Black Duck (Synopsys), I led teams, mentored junior consultants, and delivered executive-level security roadmaps to C-suite stakeholders.
My proudest achievement: discovering and responsibly disclosing 3 CVEs — CVE-2024-35581, CVE-2024-35582, CVE-2024-35583 — now published in the MITRE and NVD databases.
git log --experience
ls -la ./arsenal
cat ./advisories/*.md
lname (Borrower Name) field in the Borrow workflow. Payload executes in the authenticated admin context on the borrow view page, enabling session theft and account takeover.department field of the same Borrow workflow — the second of three unencoded fields on one render sink, confirming a systemic missing output-encoding layer.remarks field. Persistent payload re-fires for any user — including higher-privileged accounts — who opens the affected borrow record.cat ./hall-of-fame.log
ls ./research-and-tools
./connect --now
Whether you're looking for a security assessment, want to discuss a CVE, need a consultant for your enterprise, or just want to talk offensive security — my inbox is always open.