D1
Application and product security
Application security reviews and red team assessments on internal and
cloud-native applications, secure code review across Python, Java,
JavaScript, and C#, Android and iOS application testing, and security
controls designed into feature planning and architecture reviews.
Representative methods & tools
OWASP Top 10 · API security (OAuth2, JWT) · Burp Suite · OWASP ZAP · IBM
AppScan · Acunetix · MobSF · Frida · Objection
Evidenced in
U.S. Bank,
Netsurion, and
open-source security contributions.
D2
Cloud, infrastructure, and container security
AWS security controls for least privilege and activity monitoring, network
segmentation and firewall and NAC reviews, and hardening of Docker and
Kubernetes workloads with policy-as-code.
Representative methods & tools
AWS IAM · AWS KMS · AWS CloudTrail · Docker · Kubernetes RBAC and network
policies · Checkov · OPA · Kyverno · Trivy
Evidenced in
U.S. Bank,
Netsurion, and
LanceSoft.
D3
Security automation and DevSecOps
SAST, DAST, and container scanning embedded into CI/CD, Semgrep policies and
pre-commit hooks for developers, Terraform infrastructure-as-code checked
with policy tools, and task automation in Python and PowerShell.
Representative methods & tools
Semgrep · SonarQube · OWASP ZAP · GitHub Actions · Jenkins · Terraform ·
pre-commit hooks · Python · PowerShell · Bash
Evidenced in
U.S. Bank,
LanceSoft, and
CI/CD security automation work.
D4
Incident response, threat modeling, and compliance
Log analysis, incident containment, and root-cause investigation with
Splunk, STRIDE threat models and risk assessments, and alignment to PCI DSS,
HIPAA, NIST, and ISO 27001.
Representative methods & tools
Splunk · ELK · STRIDE · MITRE ATT&CK · digital forensics · PCI DSS ·
HIPAA · NIST · ISO 27001
Evidenced in
U.S. Bank and
LanceSoft.
D5
Mobile and AI/ML security evaluation
Adversarial evaluation of AI/ML models through evasion and poisoning
simulations, model robustness review, ML pipeline threat modeling, and
review of model APIs, training-data integrity, and access controls,
alongside mobile application security testing.
Representative methods & tools
Adversarial ML (evasion, poisoning) · model robustness evaluation · ML
pipeline threat modeling · MobSF · Frida · APKTool · Ghidra
Evidenced in
U.S. Bank,
LanceSoft, and the
featured AI/ML threat-modeling work below.