Security Engineer @ SproutXP
Breaking things on purpose, so nobody else can.
- π‘οΈ Security Engineer at SproutXP, working across application security, cloud security, and offensive testing.
- π I spend my days on penetration testing, vulnerability research, threat modeling, and secure code review.
- π€ Big believer in security automation β if I do it twice manually, I script it.
- π Always learning: exploit development, cloud attack paths, and detection engineering.
- π¬ Ask me about AppSec, red teaming, DevSecOps, or hardening CI/CD pipelines.
Languages
Security
Cloud & Infra
| Area | Focus |
|---|---|
| π΅οΈ Offensive Security | Web, API, and network penetration testing |
| π§ͺ AppSec | Secure code review, SAST/DAST, dependency risk |
| βοΈ Cloud Security | IAM hardening, misconfiguration hunting, attack paths |
| βοΈ DevSecOps | Shifting security left in CI/CD pipelines |
| π Detection | Logging, alerting, and incident response tooling |
"Security is not a product, but a process." β Bruce Schneier