Senior network engineer turned pentester. eJPT certified, in-house pentesting experience since 2022, and a growing focus on web application security — documented here, one finding at a time.
Auth flaws, access control, SSRF, injection, and business logic issues — tested the way I'd explain them to the business that owns the app.
Internal and external network assessments, built on years of running the infrastructure I now test.
A niche most testers don't have: hands-on experience with Asterisk variants, Avaya, Kamailio, and other carrier-class switching platforms, from the inside.