PROJECTS
High-Traffic E-Commerce Website Hardening
2023
Security review and hardening of an online store processing thousands of card transactions daily.
Details:
- Analyzed checkout, payment gateway integration, and customer account flows.
- Implemented stricter rate limits and bot detection to prevent card testing attacks.
- Recommended CSP, HSTS, and modern security headers across the platform.
Outcome line:
Result: Fraud-related incidents dropped significantly after launch of new controls.
Security Architecture Review for Growing Startup
2022
Advisory project to design a scalable, secure architecture for a B2B SaaS product in rapid growth.
Details:
- Mapped data flows, trust boundaries, and third-party integrations.
- Recommended segmentation, secrets management, and logging/monitoring strategy.
- Defined a practical secure SDLC, including threat modeling and security gates.
Outcome line:
Result: Leadership adopted the roadmap as the foundation of their long-term security program
API Security Assessment for Mobile App Backend
2023
Targeted penetration test of a REST API that powers iOS and Android apps for a mobility startup.
Details:
- Discovered insecure direct object references and missing authorization checks.
- Demonstrated privilege escalation scenarios using crafted API calls.
- Worked with engineers to design a consistent authorization model and test suite.
Outcome line:
Result: Closed all high-severity issues before public rollout to 100K+ users.
SaaS Platform Web App Penetration Test
2024
Full-scope penetration test of a multi-tenant SaaS platform handling sensitive financial data, combining black-box and white-box approaches.
Details:
- Identified critical IDOR and broken access control issues between tenants.
- Exposed weaknesses in session management and password reset flow.
- Provided prioritized remediation plan and re-tested after fixes.
Outcome line:
Result: Zero critical findings in the follow-up test and successful external compliance audit.
Secure Code Review & Developer Training
2022
Combined code review and hands-on training for a distributed development team building internal tools.
Details:
- Audited critical modules for injection, XSS, and broken authentication issues.
- Created tailored examples based on real findings from their codebase.
- Delivered virtual workshops on secure coding practices and common anti-patterns.
Outcome line:
Result: Teams began catching many issues themselves during code review, reducing security bugs reaching production.
Incident Response & Post-Breach Hardening
2021
Brought in after a suspected compromise of a small agency’s client portal to investigate and rebuild trust.
Details:
- Assisted with log analysis, root-cause identification, and containment.
- Cleaned and rebuilt affected components with stronger authentication and audit trails.
- Helped communicate findings and remediation steps transparently to clients.
Outcome line:
Result: No further malicious activity detected; agency continued operations with improved security posture.
High-Traffic E-Commerce Website Hardening
2023
Security review and hardening of an online store processing thousands of card transactions daily.
Details:
- Analyzed checkout, payment gateway integration, and customer account flows.
- Implemented stricter rate limits and bot detection to prevent card testing attacks.
- Recommended CSP, HSTS, and modern security headers across the platform.
Outcome line:
Result: Fraud-related incidents dropped significantly after launch of new controls.
API Security Assessment for Mobile App Backend
2023
Targeted penetration test of a REST API that powers iOS and Android apps for a mobility startup.
Details:
- Discovered insecure direct object references and missing authorization checks.
- Demonstrated privilege escalation scenarios using crafted API calls.
- Worked with engineers to design a consistent authorization model and test suite.
Outcome line:
Result: Closed all high-severity issues before public rollout to 100K+ users.
Security Architecture Review for Growing Startup
2022
Advisory project to design a scalable, secure architecture for a B2B SaaS product in rapid growth.
Details:
- Mapped data flows, trust boundaries, and third-party integrations.
- Recommended segmentation, secrets management, and logging/monitoring strategy.
- Defined a practical secure SDLC, including threat modeling and security gates.
Outcome line:
Result: Leadership adopted the roadmap as the foundation of their long-term security program.
SaaS Platform Web App Penetration Test
2024
Full-scope penetration test of a multi-tenant SaaS platform handling sensitive financial data, combining black-box and white-box approaches.
Details:
- Identified critical IDOR and broken access control issues between tenants.
- Exposed weaknesses in session management and password reset flow.
- Provided prioritized remediation plan and re-tested after fixes.
Outcome line:
Result: Zero critical findings in the follow-up test and successful external compliance audit.
Secure Code Review & Developer Training
2022
Combined code review and hands-on training for a distributed development team building internal tools.
Details:
- Audited critical modules for injection, XSS, and broken authentication issues.
- Created tailored examples based on real findings from their codebase.
- Delivered virtual workshops on secure coding practices and common anti-patterns.
Outcome line:
Result: Teams began catching many issues themselves during code review, reducing security bugs reaching production.
Incident Response & Post-Breach Hardening
2021
Brought in after a suspected compromise of a small agency’s client portal to investigate and rebuild trust.
Details:
- Assisted with log analysis, root-cause identification, and containment.
- Cleaned and rebuilt affected components with stronger authentication and audit trails.
- Helped communicate findings and remediation steps transparently to clients.
Outcome line:
Result: No further malicious activity detected; agency continued operations with improved security posture.
Questions & Answers
What types of projects do you usually work on?
I mainly work on web application and API penetration tests, e-commerce security reviews, security architecture consulting, and secure development training. Most engagements are focused on protecting customer data, payment flows, and internal tools that support critical business processes.
How do you scope a new security project?
We start with a short call where you describe your product, infrastructure, and goals. From there, I propose a scope that balances risk, budget, and timelines — clearly outlining what will be tested, which environments will be used, and what deliverables you’ll receive.
Will testing affect the stability of our live systems?
All tests are designed to be safe and controlled. Wherever possible, I recommend using staging or pre-production environments that closely mirror production. If live testing is required, we agree on strict guardrails and monitoring so your systems remain stable.
What does the final report look like?
You receive a structured report with an executive summary, technical details, proof-of-concepts, risk ratings, and a prioritized remediation plan. I also offer a review call to walk your team through every finding and answer questions.
Can you help our team fix the issues you find?
Yes. I regularly collaborate with engineering teams to clarify findings, discuss mitigation options, and validate fixes. Follow-up testing can be scheduled to confirm that vulnerabilities have been properly resolved.
How far in advance should we book a project?
My schedule tends to fill up a few weeks ahead. If you have a critical release or audit coming, it’s best to reach out as early as possible so we can secure a slot and plan the engagement properly.
