At Thinsil Technologies, I perform end-to-end security assessments across web applications, RESTful APIs, internal networks, cloud environments, and mobile applications.
I use Burp Suite and Postman to uncover broken access control, IDOR, injection flaws, JWT misconfigurations, CSRF, and business-logic bypasses, then provide actionable remediation guidance to development teams.
I assess AWS environments for IAM, S3, and security-group misconfigurations; test Android and iOS applications with MobSF and Frida; and review Cloudflare WAF rules to strengthen protection against SQL injection, XSS, bots, and unauthorized access.
I also build Python automation for race-condition detection and credential testing, integrate Wazuh monitoring for real-time threat detection, and have developed security-focused web applications using ChaCha20, ECC, AWS, and layered Cloudflare defenses.

