// about

I work in security.
Across the whole surface.

Security practitioner — CISO and lead consultant by day, researcher by habit. I spend my time on the things that actually reduce risk: tracking vulnerabilities that matter, running ISMS and audits, thinking about threat models and architecture, and — when a scope allows it — hunting bugs. This blog is where I write it down.

// what I do

Vulnerability and CVE management, ISMS and ISO 27001, IT risk, secure architecture, cloud and identity, and offensive testing when it fits. Not chasing every headline — figuring out what a given CVE, advisory, or control change actually means for the systems and people it touches.

Same discipline whether I'm defending or attacking: understand the system, find where reality and intent disagree, and prove it before I write it up. Evidence over hunches.

// skills

  • Vulnerability Mgmt
  • CVE / KEV Tracking
  • ISMS / ISO 27001
  • IT Risk
  • Threat Intel
  • Secure Architecture
  • Cloud & Identity
  • Auth / AuthZ Flaws
  • Web App Security
  • API Testing
  • Recon / OSINT
  • Report Writing

// rules

Scope is law. I don't touch systems outside defined program boundaries — not even a ping. Proof of concept without causing harm. Document everything. Submit nothing without review.

The line between security research and crime is authorization. I stay on the right side of it.

// find me

HackerOne