Curiosity is where my security work starts.

I like tracing a security issue back to its cause: the assumption in application code, the missing check, or the activity that stands out in a log. My graduate studies in Computer Science give me a foundation for this work, while practical projects help me connect concepts to real security problems.

At Toyota Insurance Management Solutions, I explored how security tooling fits into a developer’s workflow. My internship included configuring and testing a Semgrep SAST pilot in Bitbucket Pipelines, validating findings, working with SAST/SCA tools, and training developers on secure development tooling. It helped me see the value of clear findings and practical guidance when supporting secure development.

My earlier work in log analysis and incident investigation still shapes how I approach application security: follow the evidence, check assumptions, and explain what happened. I bring that approach to projects involving AI-assisted vulnerability analysis, alert triage, and AWS threat detection.

I’m interested in how AI can help with security analysis and in the security challenges AI-powered applications introduce. Building and testing these projects gives me a way to explore both interests.

What I’m Practicing

Through PentesterLab, I’m developing my web application security and secure code review skills. I focus on understanding vulnerable code, following how inputs are handled, and connecting application behavior to the underlying weakness.

Tools & Practices

  • Semgrep and SAST/SCA tooling
  • Bitbucket Pipelines and CI/CD security
  • Secure SDLC and OWASP Top 10
  • AWS security and AWS Inspector
  • Python and AI-assisted automation
  • Log analysis and SOC alert triage

How I Work Through a Finding

I start by understanding the context, then investigate whether the evidence supports the finding. From there, I consider its impact and document practical next steps. When I use AI to assist with analysis, I review its output against the code, logs, or other evidence rather than treating the generated answer as a conclusion.