Services
Video meeting . 15 mins
About me
I’m a Product Security Engineer at mPokket, driving secure-by-design engineering across our fintech platform.
With a strong foundation in offensive security (OSCP-certified, Synack Red Team), I bring a red team mindset to product and application security — from architecture reviews to threat modeling, vulnerability assessments, and hardening CI/CD pipelines.
🔐 At mPokket, I:
- Conduct secure code and design reviews across web, mobile, and cloud components
- Lead threat modeling sessions and drive remediation for high-impact flaws
- Build internal tooling for DAST/SAST/SBOM automation in CI/CD
- Work closely with DevOps and product teams to bake security into the SDLC
- Simulate real-world attacks and report vulnerabilities via internal bug bounty process
Beyond my day job, I actively participate in bug bounty programs, where I’ve discovered and responsibly disclosed critical vulnerabilities across web, mobile, and cloud environments.
I thrive at the intersection of offensive research and secure engineering, constantly seeking better ways to bridge dev, ops, and security.
🛠 Tech: Burp Suite, Semgrep, Harden-Runner, Trivy, Syft, Docker, GitHub Actions, AWS, OWASP Zap
📚 Domains: AppSec, Mobile Security (iOS/Android), Cloud Security, CI/CD Security, Bug Bounty
🎯 Certifications: OSCP | Working towards OSCE3
Let’s connect if you're building secure systems — or trying to break them. 😉