whoami
DevSecOps Engineer | Security Researcher
I do security engineering at a NYC real-estate tech company — building infrastructure, automating defenses, and breaking things politely. Off the clock: tools, OSINT, and puzzles hidden in plain sight.
AWS • GCP • Azure • Terraform • Kubernetes • Docker • CI/CD Pipelines
SIEM • Vulnerability Scanning • Penetration Testing • Threat Modeling • IDS/IPS
Python • Go • Bash • API Security • Secure Code Review
SOC2 • NIST • ISO 27001 • Security Audits • Risk Assessment
Vulnerability Research • Reverse Engineering • CTF • Malware Analysis
Curated security news — government advisories, research, and vendor intel, aggregated and distilled into one feed.
Client-side security tools — ciphers, hashing, JWT inspection, secret generation. Everything runs in your browser; nothing is transmitted.
Static, no trackers, hardened headers. The source rewards a close read.