[ clearance: top-secret (fictional) ] uptime: 9 years
I break things
so others can't.
>
ls ./projects
Things I've built and broken. All fictional for the demo. Swap in your own.
Sentinel
rust / kafka / mlThreat detection pipeline scoring 4M auth events per second. Flags credential stuffing in under 300ms. Account takeovers down 71%.
Vaultline
go / mtls / kmsZero-trust secrets service. Short-lived creds, automatic rotation, adopted by 400 internal teams.
Fuzzforge
c++ / llvm / k8sContinuous fuzzing wired into CI. Caught 38 memory-safety bugs in parsers before they shipped.
Redline
python / att&ck / awsAdversary-simulation framework mapped to MITRE ATT&CK for quarterly purple-team exercises.
Pathwatch
typescript / neo4j / iamGraph of cloud permissions showing how one stolen token reaches production customer data.
tlsprobe
go / open sourceCLI that audits TLS configs across a fleet. 3.2k stars, featured in two conference workshops.
cat advisories.log
Fictional disclosures with placeholder IDs. Hover the redacted bits.
| ID | Severity | Finding |
|---|---|---|
| CVE-DEMO-001 | CRITICAL 9.8 | Pre-auth RCE in a major cloud gateway via request smuggling |
| CVE-DEMO-002 | CRITICAL 9.1 | OAuth redirect bypass leading to full account takeover |
| CVE-DEMO-003 | HIGH 8.2 | Heap overflow in an image parser reachable from a mobile messaging app |
| CVE-DEMO-004 | HIGH 7.5 | SSRF to cloud metadata service in a webhook feature |
git log --career
Company names are fictional placeholders.
Staff Security Engineer
Halcyon CloudLead application security for the identity platform. Own the threat model, bounty triage, and secure-by-default libraries used by 3,000 engineers.
Senior Software Engineer
Northwind SystemsBuilt payment services moving $2B a year. Put threat modeling into design reviews and led the zero-trust network migration.
Software Engineer
Vantage LabsFull-stack and infra. Switched to security after leading incident response on a major breach at 3 a.m.
which --all
Builder first, breaker second.
build
Rust, Go, TypeScript
Python, C++, SQL
Distributed systems
Kubernetes, Terraform
attack
Pentesting, red teaming
Fuzzing, reverse engineering
Burp, Ghidra, Metasploit
Exploit development
defend
Threat modeling
Detection engineering
Incident response
Zero trust, IAM, crypto
Let's get in.
sonikgamingnp@gmail.comPGP: 4F2A 9C1D 77B0 E3A8 51D6 0B9E C4F3 2A18 7D5E 90AB (fictional)