About
I'm Andrew, a Senior Application Security Engineer and penetration tester.
I have 10+ years of experience in IT, with a focus on offensive security, application security, and product security. I test web, API, mobile, desktop, and AI-enabled applications, and help engineering teams secure products throughout the SDLC.
Most of that work is hands-on: penetration testing and code review, threat modeling, SAST/DAST/SCA integration, vulnerability management, and bug bounty programs. More recently it has also covered security requirements for AI agents and MCP integrations.
I build security tooling alongside the testing, and I write here about the parts of the work that turn out to be useful to other practitioners.