I’m a senior security engineer at Amazon and a penetration tester specialising in web and API security. I came up through full-stack engineering and still write code daily. That background lets me bridge engineering and security: when I break something, I also understand how it was built and how to fix it so the issue does not return.
I have more than 15 years of experience in security. For the past six years, my full-time focus has been solving complex security problems at scale and finding high-impact vulnerabilities.
Most of my work is offensive: leading deep-dive penetration tests and investigating authentication flows, API design decisions, and cross-service trust boundaries. I care most about identifying the pattern behind a vulnerability, fixing its root cause, and putting defenses in place so entire classes of bugs stop recurring.
Outside my day-to-day work, I create hands-on security education through Uphack and build tools that automate parts of my penetration-testing methodology.
Through Uphack, I turn my knowledge into practical educational content that makes abstract security concepts easier to recognise in real systems. I write about how vulnerabilities emerge, how systems fail, and how engineers can build stronger security intuition through practice. I also share what I’m learning about software engineering in the AI era and the often-unspoken lessons behind a sustainable career in security.