I'm a Security Researcher and Penetration Tester with hands-on experience in web development, focused on bug hunting and securing modern web applications.
When not coding or hunting vulnerabilities on platforms like HackerOne and Intigriti, I document security research, contribute to open-source security tools, and continuously explore emerging cybersecurity trends to strengthen real-world defenses.
Technical expertise applied through hands-on experience in web development and cybersecurity
Freelance & Contract Work
2023 - PresentBuilding responsive, secure web applications with focus on performance optimization and security-first development practices.
Bug Hunting & Analysis
2024 - PresentIdentifying and responsibly disclosing web vulnerabilities through systematic research and manual testing techniques.
Security Assessment
2025 - PresentConducting security assessments following OWASP standards with focus on risk analysis and remediation guidance.
Technical Documentation
2025 - PresentCreating detailed vulnerability reports and educational content to advance cybersecurity awareness and knowledge sharing.
Professional security assessment approach based on OWASP and industry standards
Gathering intelligence about target systems, identifying attack surfaces, and mapping the application structure.
Identifying security weaknesses through automated scanning and manual testing techniques.
Responsibly exploiting identified vulnerabilities to validate impact and demonstrate business risk.
Assessing the extent of access gained and identifying potential lateral movement opportunities.
Documenting findings with clear technical details, risk ratings, and actionable remediation steps.
Verifying that security vulnerabilities have been properly addressed and validated after fixes.
Comprehensive testing against OWASP Top 10 vulnerabilities with emphasis on business impact
A selection of my recent work in development and security
A fully functional calculator with advanced features including scientific operations and a clean, responsive UI.
A fully playable chess game with move validation, check detection, and a clean intuitive interface.
Real-time phishing detection tool that analyzes URLs for suspicious patterns, malicious indicators, and security threats.
Real-time password strength analyzer that estimates crack time using GPU-speed & character-set detection.
Live port scanner that tests 20+ network ports and detects open services in real-time.
A custom web application scanner that detects common security vulnerabilities like XSS, SQLi, and CSRF.
Acknowledged for professional security research and responsible disclosure practices across leading platforms.
Recognized for multiple critical vulnerability discoveries with detailed technical reports across enterprise programs.
Acknowledged for consistent, high-quality security findings with professional collaboration across private programs.
Contributing to security research programs with focus on web application vulnerabilities and API security testing.
Building trust through responsible security research and professional collaboration.
Committed to making the digital ecosystem safer through detailed disclosure and ethical practices.
Weekly insights on bug bounty findings, penetration testing techniques, and security research
Have a project in mind or need security advice? Let's talk!
Thank you for reaching out. I'll get back to you as soon as possible.