Application Security Engineer | Backend Engineering Background
Application security engineer with a decade of production backend experience, auditing code and infrastructure for real-world vulnerabilities, leading incident response on live compromises, and building tools that surface security risk before attackers do. Hands-on work spans vulnerability analysis (IDOR, type juggling, mass assignment, deserialization), infrastructure hardening, and secrets/access auditing, backed by a decade of Laravel/PHP systems experience that shapes how I think about attack surface. Currently expanding that practice through OSINT and security-auditing tools (TraceTrellis, SIGIL, VaultCheck) and a running vulnerability research series (DVLA).
Security Engineering Case Studies
TraceTrellis
A full-stack OSINT platform that aggregates 16 data sources in parallel, breach records, domain security posture, SSL, open ports, and more.
SIGIL
A manifest-driven infrastructure hardening engine for LEMP stacks. Generates auditable, reproducible hardening scripts from a declarative YAML manifest.
VAULTCHECK
A CLI tool that audits the hygiene and risk posture of how secrets and environment variables are managed, reasoning about the full lifecycle of how secrets enter, drift, leak, and go stale.
Latest Writing
Stored XSS in Laravel: No Account Needed When the Sink Is the Admin's Own Session
You don't need a login to plant this one. A message left through a public contact form sits quietly in the database until an admin opens the page to review submissions, then wakes up and runs inside their session, no password stolen, no cookie needed.
Areas of Proficiency
Application Engineering
Static and dynamic analysis across the PHP/Laravel stack, including type-juggling bypasses, Eloquent mass-assignment flaws, IDOR, and access-control failures. Tooling includes PHPStan/Larastan, Psalm taint analysis, and Nuclei. Direct incident response experience: detection and remediation of a production backdoor with C2 infrastructure, followed by custom file-integrity tooling and nginx hardening across multiple live sites.
Backend Engineering
A decade of production PHP and Laravel development, with Livewire for reactive interfaces. Recurring work includes custom CMS/CRM builds, authentication systems, secure API integrations, and infrastructure management across Linode VPS environments (nginx, PHP-FPM). I build with the assumption that production systems fail through chains of individually defensible decisions, not single obvious mistakes, which shapes how I approach both development and review.





