I've delivered full-scope web application and REST API pentests for DB clients in retail, auto parts, and finance, uncovering race conditions, MFA bypasses, and chained vulnerabilities that exposed sensitive customer data.
Previously at Pacific Sec, I tested web applications, REST, GraphQL, and SOAP APIs, and thick clients across financial, healthcare, retail, industrial, legal, and technology sectors. I progressed from individual contributor to technical reference, mentoring junior analysts and translating complex findings into clear technical and executive risk reports using OWASP and MITRE ATT&CK methodologies.

