Security should scale with engineering, not compete against it.
For more than seven years, my work has evolved from QA Automation into DevOps, DevSecOps and Application Security, building production-ready engineering systems where security is embedded throughout the software delivery lifecycle.
That work spans cloud-native infrastructure, CI/CD platforms, Infrastructure as Code, observability, software supply chain security and policy-driven controls, together with Application Security practices including secure code review, vulnerability analysis, threat modeling and security automation. The focus is always the same: helping engineering teams deliver software quickly, reliably and securely.
A Master of Science in Information Technology earned in Massachusetts, USA, together with hands-on industry experience, shaped an engineering-first perspective where security is treated as a design decision rather than a compliance exercise.
AppSec Forge is a continuation of that philosophy: a growing GitHub-based collection of production-grade security cases built around realistic engineering scenarios rather than intentionally vulnerable examples. Covering source code, infrastructure, cloud platforms, CI/CD, software supply chains and AI, every case starts with the engineering decision that introduced the vulnerability and follows it through analysis, exploitation, remediation, prevention and detection.
The goal is simple: bridge the gap between security theory and the engineering decisions that shape real-world systems.
Every vulnerability starts as an engineering decision.
Secure software is the outcome of engineering discipline, not security afterthoughts.
