Security engineer working on application security and offensive research. I review code and design across Go, Java, Python, and JavaScript, drive threat modeling on high-risk flows, and build automation that scales that work.
Five CVEs, and Hall of Fame recognition from Google and Mozilla. Exploits published on PacketStorm.
Pull requests merged into repositories I don't own, ordered by the star count of the project. Click a contribution to open the pull request.
- Bypassing a 3 layer SVG sanitizer: Stored XSS in Mozilla. The bypass, the parser differential, and the missing
write().
Threat modeling (STRIDE) Secure code review SAST/DAST API security Supply chain security Exploit development Sanitizer bypass analysis AWS GCP CI/CD hardening