I build and share cybersecurity tools, with a focus on AI security, web application security, and API security.
| Project | What It Does |
|---|---|
| Web App Security Portfolio | Hands-on web application security projects — vulnerability research, secure coding patterns, and offensive/defensive techniques |
| Security Architecture Fundamentals | Practical security architecture reference — cloud design patterns, threat modeling, risk assessment, and framework mappings (NIST, CIS, MITRE) |
| Detection Engineering Lab | Hands-on detection-as-code lab — Wazuh SIEM rules with MITRE ATT&CK mappings, Terraform-deployed infra, threat emulation coverage |
Languages: Python, Go, Bash, PowerShell, HCL
Cloud & Infra: AWS (Lambda, API Gateway, Bedrock, DynamoDB, CloudWatch), Azure (Sentinel, Defender, Firewall), GCP (SCC, Chronicle, KMS), Terraform, GitHub Actions CI/CD
Security: LLM threat modeling, prompt injection detection, PII scanning, SIEM/detection engineering, network traffic analysis, bug bounty tooling
Frameworks: FastAPI, httpx, boto3, Scapy, Cobra





