- Application Security — web application pentest and API's, threat modeling, security code review
- Infrastructure & Network — inner pentest, AD, post-exploitation
- DevSecOps — SAST/DAST/SCA в CI/CD, vulnerability management, continuous monitoring
- Development — Java/Spring, React/TypeScript
Most of the pentesters doesn't write production - ready code. Most of the developers doesn't think as an attacker. I`m doing both things. Thats why in my report presents patches, not a list of CVE's.
Offensive
Defensive / DevSecOps
Certifications



