Security by Design

Viktor A. Gurko

Viktor A. Gurko

Security should scale with engineering, not compete against it.

For more than seven years, my work has evolved from QA Automation into DevOps, DevSecOps and Application Security, building production-ready engineering systems where security is embedded throughout the software delivery lifecycle.

That work spans cloud-native infrastructure, CI/CD platforms, Infrastructure as Code, observability, software supply chain security and policy-driven controls, together with Application Security practices including secure code review, vulnerability analysis, threat modeling and security automation. The focus is always the same: helping engineering teams deliver software quickly, reliably and securely.

A Master of Science in Information Technology earned in Massachusetts, USA, together with hands-on industry experience, shaped an engineering-first perspective where security is treated as a design decision rather than a compliance exercise.

AppSec Forge is a continuation of that philosophy: a growing GitHub-based collection of production-grade security cases built around realistic engineering scenarios rather than intentionally vulnerable examples. Covering source code, infrastructure, cloud platforms, CI/CD, software supply chains and AI, every case starts with the engineering decision that introduced the vulnerability and follows it through analysis, exploitation, remediation, prevention and detection.

The goal is simple: bridge the gap between security theory and the engineering decisions that shape real-world systems.

Every vulnerability starts as an engineering decision.

Secure software is the outcome of engineering discipline, not security afterthoughts.