I am an Application Security Engineer grounded in backend engineering. My professional work focuses on application security, including Secure SDLC guidance, vulnerability management, and helping application teams address risk earlier in the delivery lifecycle.
My portfolio projects lean into DevSecOps security automation: CI/CD pipeline proof-of-concepts and practical delivery controls using SAST, dependency scanning, container scanning, secret scanning, and SBOM generation. This project specialization supports my AppSec work; it is not a separate job title.
At BSI UII, I started by building and maintaining backend services for student scholarship systems before moving into SOC/CISRT work. That progression shapes how I approach security: controls should fit the way developers build and ship software.
My core stack includes Go, PHP, Laravel, REST APIs, Docker, Kubernetes, and OpenBao, supported by Linux, Nginx, GCP, and Cloudflare. I use this website to document DevSecOps projects, security labs, backend patterns, and lessons from building safer delivery workflows.





