Proof through practice: my dual pentest-and-development skillset, in action.
Explore the skills graph
Securing the company's web and mobile applications — regular penetration testing, industrialising security in the CI/CD pipeline, and fixing flaws directly in the backend code.

Penetration testing on the company's web applications — identifying vulnerabilities (SQL injection, RCE, XSS…), writing remediation tickets for developers and following up on fixes.

Internal infrastructure pentest — network mapping (Nmap), enumeration and vulnerability hunting on an Active Directory environment, reported in an audit deliverable.