Security analyst specializing in threat detection and incident response. I find what shouldn't be on the network, and I explain, in plain language, what to do about it.
I've spent the last five years as a mobile and web developer — shipping Flutter, Kotlin and Vue apps, building APIs, and designing interfaces people actually enjoy using. Along the way I kept running into the same question: once you've built something, how do you know it's actually safe? That question is what pulled me toward security.
I'm early in the transition and I'd rather be upfront about that than dress it up. Right now that means structured coursework through Cisco's Networking Academy and hands-on practice in PortSwigger's Web Security Academy, with a home lab and public write-ups planned next. My developer background gives me a head start on understanding how applications actually work — which I think matters just as much as knowing how to break them.
Working through Cisco's cybersecurity and networking coursework — building the foundation in network fundamentals, threats, and defense that most security roles assume you already have.
Working through the free Web Security Academy labs — SQL injection, XSS, auth flaws, and the rest of the OWASP-adjacent basics. My web dev background helps here; I already know what the code on the other side of these bugs usually looks like.
Setting up a personal lab environment to practice against, with the goal of documenting everything publicly — CTF attempts, lab notes, and small projects — on GitHub and a companion blog.
Solid ground from five years of development, and the security layer being built on top of it right now. Solid green = established. Diagonal cyan = currently training.
Nothing filed yet — this section is reserved for lab write-ups, CTF attempts, and small projects as they're documented on GitHub and the blog.
Walkthroughs of TryHackMe / PortSwigger labs as I work through them — what broke, what I tried, what actually worked.
Building a small home lab to practice network defense and attack scenarios safely, documenting the setup for anyone starting the same path.
Short posts on what looks different once you start reading your own past code through a security lens.
I'm open to entry-level security roles, internships, and honestly, advice from anyone further along this path than I am.