I work in security.
Across the whole surface.
Security practitioner — CISO and lead consultant by day, researcher by habit. I spend my time on the things that actually reduce risk: tracking vulnerabilities that matter, running ISMS and audits, thinking about threat models and architecture, and — when a scope allows it — hunting bugs. This blog is where I write it down.
// what I do
Vulnerability and CVE management, ISMS and ISO 27001, IT risk, secure architecture, cloud and identity, and offensive testing when it fits. Not chasing every headline — figuring out what a given CVE, advisory, or control change actually means for the systems and people it touches.
Same discipline whether I'm defending or attacking: understand the system, find where reality and intent disagree, and prove it before I write it up. Evidence over hunches.
// skills
// rules
Scope is law. I don't touch systems outside defined program boundaries — not even a ping. Proof of concept without causing harm. Document everything. Submit nothing without review.
The line between security research and crime is authorization. I stay on the right side of it.