Cybersecurity engineer and software developer. I work across offensive and defensive security, network engineering, database systems, and low level development. Most of my time goes into hardening infrastructure, analyzing traffic and binaries, and building the tooling that supports both.
All security work is performed under written authorization and within an agreed scope.
Offensive Security
Penetration testing, vulnerability research, exploit development, reverse engineering, binary analysis, red team operations, social engineering assessment.
Defensive Security
Threat detection, incident response, malware analysis, digital forensics, SIEM engineering, log correlation, security hardening, blue team operations.
Network Engineering
Routing and switching, firewall architecture, network segmentation, VPN and tunneling, packet analysis, intrusion detection, infrastructure monitoring.
Database Engineering
Schema design, query optimization, indexing strategy, replication and clustering, backup and recovery, access control, injection prevention, database hardening.
Systems and Software
Systems programming, kernel level development, cross platform desktop applications, backend services, security automation and internal tooling.
Relational and non relational systems in production. Work covers normalization and schema design, execution plan analysis and query tuning, index strategy, master and replica replication, connection pooling, transaction isolation and deadlock resolution, encryption at rest, least privilege access models, and parameterized query enforcement to eliminate injection surface.
Linux: Kernel internals, process and memory management, systemd service architecture, filesystem permissions and ACLs, SELinux and AppArmor policy, iptables and nftables, namespaces and cgroups, package management across Debian, RHEL, and Arch families.
Windows: Active Directory and domain architecture, Group Policy, registry internals, NTFS permissions, Windows Event Log analysis, PowerShell administration and remoting, LSASS and credential protection, Defender and AppLocker policy.
BSD and Unix: FreeBSD jails, pf firewall configuration, ZFS storage management, and Unix permission and process models.
Protocol level work across TCP/IP, BGP, OSPF, VLAN and trunking, NAT, DNS, DHCP, TLS, and 802.1X. Firewall rule design, network segmentation, and traffic inspection at both the perimeter and internal boundaries.