Skilled in Burp Suite, OWASP ZAP, Nmap, SAST, DAST, SCA, Azure DevOps, GitHub Actions, SonarQube, AWS Security, Docker, and vulnerability management. I have implemented security controls into CI/CD pipelines, performed threat modeling and architecture reviews, and worked closely with development teams to drive secure-by-design practices.
I am also an active security researcher with 350+ vulnerabilities reported through HackerOne and Bugcrowd, with recognition from organizations including Google, Microsoft, Apple, and Sony.
Available for Application Security, Penetration Testing, DevSecOps, and Security Consulting projects, including remote and freelance engagements.