Google Professional Cybersecurity Certificate
Google · Coursera
Completed: 2026
Software Engineer · Application Security & AI Systems
Full-Stack Engineer focused on Application Security.
Shipping web systems with security as a design input, not an afterthought.
I work the layer where shipping fast meets shipping safe — auth, sessions, tokens, RBAC, and the OWASP Top 10. Offense-first, then hardened.
Five production-grade JWT flaws reproduced from scratch, then hardened against a secure mirror.
npm CLI that hunts those same bugs in tokens and live endpoints — CI-friendly exit codes.
Offense-and-defense breakdowns: alg=none bypass, HS/RS confusion, kid injection.
01 Career
2025
2025
Frontend Developer
Jul 2025 - Sep 2025
Migrated business-critical legacy modules from jQuery to React: 40% bundle-size reduction and shrunk the client-side attack surface by consolidating logic into a modular Atomic Design library. Engineered Azure CI/CD to replace manual SSH deploys, cutting deploy time from 2+ hours to <15 min and enabling automated test gates — foundation for SAST and dependency scanning.
2024
2024
Full-Stack Development
Jun 2024 - Jul 2024
Hands-on bootcamp: Linux/CLI, TypeScript, Node.js, Docker, REST APIs, WebSockets, Next.js, AWS. Foundation of how modern production systems fit together.
02 About
I'm a Full-Stack Engineer from Bogotá, Colombia, focused on Application Security and the reliability of modern web systems. I build end-to-end, React and Next.js on the front, Node, TypeScript, and PostgreSQL on the back, with attention on the layer where working code becomes a security risk.
I approach development with a security-first mindset: threat modeling features before they ship, using the OWASP Top 10 as a baseline, and validating systems through offensive testing. I actively train on platforms like TryHackMe and PortSwigger Web Security Academy to understand how real attacks work and how to prevent them.
I'm particularly interested in securing AI-integrated applications as they introduce new attack surfaces beyond traditional web security.
Open to full-time roles, freelance, or interesting side projects. If you have a problem worth solving, let's talk.
03 Credentials
Credentials backing the security pivot — completed and in progress, alongside shipped projects.
Google · Coursera
Completed: 2026
PortSwigger
Completed: All free courses
CompTIA
Target: 2026 Q3
04 Expertise
05 Work
Playable, sandboxed web-security CTF
An interactive hacking terminal you can actually play — four boxes reproducing real vulnerability classes, safely simulated in the browser with no network and no eval.
Autonomous IDOR/BOLA review, driven by Claude agents
An autonomous pentest of authorization logic in Next.js App Router repos: agents trace each client-controlled identifier to the database query it reaches and flag the ownership checks that are missing — the #1 OWASP risk that pattern-matching SAST largely misses.
Offense-and-defense LLM/RAG security lab
Two FastAPI services with the same RAG surface — one intentionally vulnerable, one hardened. Every attack in the suite succeeds against the first and fails against the second, so each fix is demonstrated rather than claimed.
Offense-and-defense JWT vulnerability lab
Offense-and-defense lab exercising real-world JWT vulnerabilities against a hardened mirror, proving each fix rather than claiming it.
Secure real-time collaborative workspace
Secure collaborative system with verified identity, hardened authentication, and a purpose-built realtime layer.
Solo-built, in-production e-commerce platform
Solo-built, in-production e-commerce platform for a family-owned hardware retailer.
06 Get in touch
Open to Software Engineer and junior AppSec roles — remote, or relocating. If you're hiring for security-minded developers, let's talk.
Or reach me directly