5+ years across product security, application security and offensive testing. Currently running DevSecOps and secure-release reviews for enterprise IBM Maximo Application Suite — SAST, DAST, SCA and container scanning, plus hands-on remediation. Previously built an organisation's entire security function from zero — process, tooling and a 5-person team. Credited by Apple, the United Nations, Dell and eBay for responsible disclosure.
A cybersecurity training range that looks like a real SaaS product — 11 realistic target apps, 48 hands-on challenges, flags & scoring, cross-app attack campaigns, a role-based admin console and an auto-detecting blue-team SOC.
Covers the OWASP Web Top 10, API Top 10 and LLM Top 10 — SQLi, XSS, SSRF, SSTI,
IDOR / BOLA, JWT alg:none, GraphQL abuse, OAuth redirect_uri, PHP object injection,
prompt injection & RAG poisoning — each scalable across four difficulty levels from textbook-vulnerable
to a hardened reference fix. Ships as one PHP + Docker container: docker compose up and it runs.
VAPT · Web / API / Mobile Pentesting · Red & Purple Teaming · Breach & Attack Simulation · VPN Testing · OWASP Top 10 · JWT / OAuth / Rate-Limit Bypass
Application & Product Security · DevSecOpsSAST · DAST · SCA · Container Scanning (Twistlock / Prisma Cloud) · Mend · OWASP ZAP · Secure SDLC · CI/CD Security · SBOM · OSS Remediation · Secure Release Review
Vulnerability ManagementCVE Analysis · CVSS Scoring · PSIRT / PVR Workflows · Remediation Tracking · Executive Reporting
Threat Hunting · Microsoft Sentinel · Defender for Endpoint · Sophos XDR · Azure WAF · Dark-Web Monitoring
Cloud & GRCAWS · Azure · Cloud Security Audits · ISO 27001 · SOC 2 · DPDP Act 2023 · Risk Assessment
ToolsetBurp Suite · OWASP ZAP · Mend · Twistlock / Prisma Cloud · Nuclei · Subfinder · httpx · Nmap · Nessus · Metasploit · Acunetix · Netsparker · Hashcat · Autopsy