PROJECTS

High-Traffic E-Commerce Website Hardening

2023

Security review and hardening of an online store processing thousands of card transactions daily.

Details:

  • Analyzed checkout, payment gateway integration, and customer account flows.
  • Implemented stricter rate limits and bot detection to prevent card testing attacks.
  • Recommended CSP, HSTS, and modern security headers across the platform.

Outcome line:
Result: Fraud-related incidents dropped significantly after launch of new controls.

Security Architecture Review for Growing Startup

2022

Advisory project to design a scalable, secure architecture for a B2B SaaS product in rapid growth.

Details:

  • Mapped data flows, trust boundaries, and third-party integrations.
  • Recommended segmentation, secrets management, and logging/monitoring strategy.
  • Defined a practical secure SDLC, including threat modeling and security gates.

Outcome line:
Result: Leadership adopted the roadmap as the foundation of their long-term security program

API Security Assessment for Mobile App Backend

2023

Targeted penetration test of a REST API that powers iOS and Android apps for a mobility startup.

Details:

  • Discovered insecure direct object references and missing authorization checks.
  • Demonstrated privilege escalation scenarios using crafted API calls.
  • Worked with engineers to design a consistent authorization model and test suite.

Outcome line:
Result: Closed all high-severity issues before public rollout to 100K+ users.

SaaS Platform Web App Penetration Test

2024

Full-scope penetration test of a multi-tenant SaaS platform handling sensitive financial data, combining black-box and white-box approaches.

Details:

  • Identified critical IDOR and broken access control issues between tenants.
  • Exposed weaknesses in session management and password reset flow.
  • Provided prioritized remediation plan and re-tested after fixes.

Outcome line:
Result: Zero critical findings in the follow-up test and successful external compliance audit.

Secure Code Review & Developer Training

2022

Combined code review and hands-on training for a distributed development team building internal tools.

Details:

  • Audited critical modules for injection, XSS, and broken authentication issues.
  • Created tailored examples based on real findings from their codebase.
  • Delivered virtual workshops on secure coding practices and common anti-patterns.

Outcome line:
Result: Teams began catching many issues themselves during code review, reducing security bugs reaching production.

Incident Response & Post-Breach Hardening

2021

Brought in after a suspected compromise of a small agency’s client portal to investigate and rebuild trust.

Details:

  • Assisted with log analysis, root-cause identification, and containment.
  • Cleaned and rebuilt affected components with stronger authentication and audit trails.
  • Helped communicate findings and remediation steps transparently to clients.

Outcome line:
Result: No further malicious activity detected; agency continued operations with improved security posture.

High-Traffic E-Commerce Website Hardening

2023

Security review and hardening of an online store processing thousands of card transactions daily.

Details:

  • Analyzed checkout, payment gateway integration, and customer account flows.
  • Implemented stricter rate limits and bot detection to prevent card testing attacks.
  • Recommended CSP, HSTS, and modern security headers across the platform.

Outcome line:
Result: Fraud-related incidents dropped significantly after launch of new controls.

API Security Assessment for Mobile App Backend

2023

Targeted penetration test of a REST API that powers iOS and Android apps for a mobility startup.

Details:

  • Discovered insecure direct object references and missing authorization checks.
  • Demonstrated privilege escalation scenarios using crafted API calls.
  • Worked with engineers to design a consistent authorization model and test suite.

Outcome line:
Result: Closed all high-severity issues before public rollout to 100K+ users.

Security Architecture Review for Growing Startup

2022

Advisory project to design a scalable, secure architecture for a B2B SaaS product in rapid growth.

Details:

  • Mapped data flows, trust boundaries, and third-party integrations.
  • Recommended segmentation, secrets management, and logging/monitoring strategy.
  • Defined a practical secure SDLC, including threat modeling and security gates.

Outcome line:
Result: Leadership adopted the roadmap as the foundation of their long-term security program.

SaaS Platform Web App Penetration Test

2024

Full-scope penetration test of a multi-tenant SaaS platform handling sensitive financial data, combining black-box and white-box approaches.

Details:

  • Identified critical IDOR and broken access control issues between tenants.
  • Exposed weaknesses in session management and password reset flow.
  • Provided prioritized remediation plan and re-tested after fixes.

Outcome line:
Result: Zero critical findings in the follow-up test and successful external compliance audit.

Secure Code Review & Developer Training

2022

Combined code review and hands-on training for a distributed development team building internal tools.

Details:

  • Audited critical modules for injection, XSS, and broken authentication issues.
  • Created tailored examples based on real findings from their codebase.
  • Delivered virtual workshops on secure coding practices and common anti-patterns.

Outcome line:
Result: Teams began catching many issues themselves during code review, reducing security bugs reaching production.

Incident Response & Post-Breach Hardening

2021

Brought in after a suspected compromise of a small agency’s client portal to investigate and rebuild trust.

Details:

  • Assisted with log analysis, root-cause identification, and containment.
  • Cleaned and rebuilt affected components with stronger authentication and audit trails.
  • Helped communicate findings and remediation steps transparently to clients.

Outcome line:
Result: No further malicious activity detected; agency continued operations with improved security posture.

FAQ

Questions & Answers

What types of projects do you usually work on?

I mainly work on web application and API penetration tests, e-commerce security reviews, security architecture consulting, and secure development training. Most engagements are focused on protecting customer data, payment flows, and internal tools that support critical business processes.

We start with a short call where you describe your product, infrastructure, and goals. From there, I propose a scope that balances risk, budget, and timelines — clearly outlining what will be tested, which environments will be used, and what deliverables you’ll receive.

All tests are designed to be safe and controlled. Wherever possible, I recommend using staging or pre-production environments that closely mirror production. If live testing is required, we agree on strict guardrails and monitoring so your systems remain stable.

You receive a structured report with an executive summary, technical details, proof-of-concepts, risk ratings, and a prioritized remediation plan. I also offer a review call to walk your team through every finding and answer questions.

Yes. I regularly collaborate with engineering teams to clarify findings, discuss mitigation options, and validate fixes. Follow-up testing can be scheduled to confirm that vulnerabilities have been properly resolved.

My schedule tends to fill up a few weeks ahead. If you have a critical release or audit coming, it’s best to reach out as early as possible so we can secure a slot and plan the engagement properly.

HAVE A PROJECT IN MIND?

Let’s Turn Your Security Risks into Actionable Insights

Scroll to Top