
I am Security oriented and eager to learn new things. Along with technical abilities I possess other necessary traits such as strong communication skills.
I like security in general. Besides over 10 years of professional experience I enjoy tinkering with software privately. I was participating in "CTF" platforms such as "ringzeroteamCTF" or "Hitcon CTF". I was testing Hitcon CTF challenges locally from repository files hosted by Orange Tsai researcher and analyzed the code with the purpose of finding security issues.
I have identified vulnerabilities in products like Mozilla Firefox, McAfee DLP or Google Chrome. There is no CVE assigned for Google Chrome however due to duplicate report but it proves that I am able to spot risks even in very popular software.
Currently I am focused to help integragrate security in entire SDLC process. I work closely with developers to give suggestions regarding security controls. I work with popular frameworks ranging from Angular for client-side to Express.js or .NET Core for backend among many others.
I have experience working with dynamic security tools like Burp-Suite for example. I am experienced on cloud based applications as well and have identified issues related to cloud-based solutions.
Currently my focus is on hands-on highly technical Security Engineering Path. Experience from Offensive side of cybersecurity can be very helpful when dealing with configurations of security tools, or generally security technology. I can run and configure scanners, verify vulnerabilities found and help provide easy to understand guidance.
I have strong application security fundamentals and I am sure I could bring value to your company.
I started as Penetration Tester in 2017.04
In 2019.06 I got a promotion to Senior Penetration Tester
eWPT- eLearnSecurity Web application Penetration Tester
CVE-2020-12412: Address bar spoofing using history navigation and blocked ports
CVE-2022-2330: XXE leading to local file disclosure
CVE-2021-37999: XSS in new tab. CVE assigned to someone else. Google VRP policy states that credit goes to first reporter and I was bit late but the point is that I am able to spot issues in popular software.
CVE-2023-2015: Reflected XSS In Report Abuse
CVE-2023-0483: Leaking Datadog API Key
CVE-2023-3909: Denial of Service
CVE-2023-1279: Incorrect "../" Parsing