I've delivered penetration testing and security assessments for web, mobile, API, thick-client, network, and cloud environments at Coforge, WeSecureApp (now Strobes), and Castellum Labs.
At WeSecureApp, I identified critical and high-severity issues including SQL injection, account takeover through improper AWS Cognito authentication handling, race conditions, and IDOR leading to unauthorized order cancellations. I also reviewed Kong API Gateway configurations, performed source code reviews, and produced actionable remediation reports.
At Coforge, I assess web and mobile applications for security and business-logic flaws, validate against OWASP Top 10 and secure coding standards, and create PoC videos, risk-based reports, and vulnerability tracking documentation.
I've also automated attack surface management and vulnerability activities with Python, contributed to threat hunting, and mentored junior team members on web application penetration testing practices.
