Application security
Manual review, threat modeling, control design, and remediation guidance for product teams.
Application security / New York
Building the sound of security.
I find the break, build the fix, and turn security work into systems that engineering teams can use.
01 / About
I am an application security engineer at Warner Music Group, based in New York. I work across product security, offensive testing, DevSecOps, and the systems that turn findings into measurable risk reduction.
My approach starts with technical depth and ends with a path teams can act on: concise evidence, realistic prioritization, and tooling that fits the way software is actually shipped.
Manual review, threat modeling, control design, and remediation guidance for product teams.
Web, cloud, and infrastructure testing that follows real attack paths and proves impact.
Automation and platform work that make repeatable security checks part of delivery.
02 / Experience
Enterprise application security, consulting, research, and secure software engineering.
Cybersecurity Engineer II / Application Security
Security Engineer Intern
Security Engineer Intern
Penetration Tester Intern
03 / Selected work
Closed source / 2026
A powerful closed-source offensive cybersecurity harness. Its public overview examines asymmetric AI warfare.
Coming soon
A defensive security project focused on measures against offensive tools such as EngineRed. More details are coming soon.
Industry research / 2026
The cybersecurity acquisition frenzy is reshaping the industry, but at what cost? A look at how billion-dollar exits can stifle genuine security innovation.
Security writeups / 2021
A collection of practical walkthroughs for TryHackMe rooms, documenting reconnaissance, web exploitation, privilege escalation, and CTF problem-solving.
Open source / 2026
A Prisma-style generator that turns OpenAPI and Swagger schemas into stable, ergonomic TypeScript without coupling teams to an HTTP client.
Competition / 2024
Led offensive security work under live-fire constraints, coordinating reconnaissance, exploitation, and reporting to place second out of 70 teams.
04 / Contact
For application security, research, open-source collaboration, or a thoughtful exchange about the field, send a note.
[email protected]