About
A developer who learned to break things properly
Web Application Security Engineer with nearly 3 years of professional AppSec experience and 7+ years building PHP web applications. I identify vulnerabilities, review insecure code, guide remediation and retest fixes across production applications.
Professional journey
I bring more than seven years of PHP web development experience and nearly three years of professional application security experience. I started by building PHP and MySQL applications for real businesses, working across authentication, customer data, payments, APIs, business workflows and Linux-hosted production environments.
My development background gradually became a security advantage. Understanding how applications are designed and implemented allows me to investigate vulnerabilities beyond scanner output, trace weaknesses back to their implementation, communicate practical remediation to developers and retest fixes after they have been deployed.
From October 2023 to August 2026, I worked as a Web Application Security Engineer with EverTrust Finance Ltd, supporting the security of a production financial-services application through manual security testing, source-code review, authentication and access-control testing, API and business-logic assessment, vulnerability remediation, retesting, security monitoring and server hardening.
Why I moved into application security
After years of building PHP applications, I became increasingly interested in how security failures happen inside real code: weak access control, unsafe input handling, insecure authentication, vulnerable APIs and business logic that works functionally but fails under hostile use.
That interest developed into structured application security work through OWASP methodology, authorised labs, secure code review and hands-on testing with tools such as Burp Suite and OWASP ZAP. The more I tested, the more valuable my development background became because I could understand not only how a vulnerability was exploited, but also why the implementation allowed it and how to fix it properly.
My PHP development background
I have more than seven years of hands-on PHP development experience building and maintaining web applications with PHP, Laravel, MySQL, HTML, CSS, Git and Linux-based hosting environments.
My work includes MVC application architecture, authentication and authorisation, customer and business workflows, REST APIs, payment gateway integrations, webhook processing, database design, server deployment and production maintenance. I have worked across shared hosting, Apache and VPS environments and continue to build and secure applications used by real users.
Staying close to development keeps my security recommendations practical. I understand how fixes affect application behaviour, architecture, delivery timelines and maintainability, which helps me work more effectively with developers during remediation.
Both perspectives, on purpose
I approach application security from both the tester's and developer's perspective. Finding a vulnerability is only part of the job; the finding needs to be reproducible, understandable and practical for the engineering team responsible for fixing it.
My security findings focus on evidence, root cause, business impact and actionable remediation. Where appropriate, I trace the weakness back to the application logic or source code, work through the remediation approach and retest the affected functionality to verify that the vulnerability has been properly resolved without breaking legitimate behaviour.
The role I am looking for
I am targeting Application Security Engineer, Web Application Security Engineer, Product Security Engineer and security-focused development roles where I can combine manual security testing, secure code review, vulnerability remediation and hands-on development experience to help engineering teams build and maintain more secure applications.
>Ethics and authorisation
Every engagement described on this website was performed with written authorisation and an agreed scope, or inside deliberately vulnerable training platforms and my own private lab. No client names, customer data, credentials, private endpoints or weaponised exploit code appear anywhere on this site.