I'm a web application security tester with a developer's background, which means I understand how the apps I'm testing are actually built. I'm eJPT-certified and finishing Hack The Box's CWES, ranked Skilled on the platform, and working through the CPTS path alongside it.
Most of my hands-on work is in web exploitation, file upload attacks, and enumeration. For a mock engagement, I wrote the Artemis penetration test report, nine findings including SQL injection and broken access control, scored by CVSS with remediation steps and an executive summary. I also built Lethe, a Python engine that models real-world password attack patterns, as a way to understand credential attacks from the inside.
Before security, I worked as a front-end developer at Flywheel, building platform features in TypeScript and Angular. That background is a big part of why I'm drawn to breaking web apps now: I've been on the building side.

