Penetration Tester | Web App, API, Cloud & Active Directory
I test web applications, APIs, cloud environments, and Active Directory, with a focus on identifying, validating, and clearly documenting security vulnerabilities.
Scanner output is a lead, not a finding. I manually reproduce and validate vulnerabilities before they reach a report, with evidence and remediation guidance that engineering teams can act on.
- Penetration Testing Methodology — A phased, evidence-based penetration testing methodology guided by NIST SP 800-115 and PTES.
- Web & API Penetration Testing — A practical testing lifecycle from reconnaissance and enumeration through exploitation, reporting, and retesting, aligned with the OWASP WSTG.
- Web Application Penetration Testing
- API Security Testing
- Active Directory Security
- Cloud Security Testing
- Vulnerability Assessment & Validation
- Reconnaissance & Enumeration
- Exploitation & Privilege Escalation
- Security Reporting & Remediation
Kali Linux · Burp Suite · Nmap · Wireshark · Metasploit · Nessus · Nikto · Gobuster · SQLmap · Python · Bash
- CompTIA Security+
- Working toward CPTS → PNPT → OSCP