I perform application security assessments across Web, API, Mobile, and Thick Client environments, owning the testing lifecycle from scoping through exploitation, proof-of-concept development, and reporting.
The work includes identifying complex vulnerabilities beyond OWASP Top 10, including business logic flaws and authorization weaknesses, and collaborating directly with developers, DevOps, and product teams on remediation guidance.