Case File 02 — About
Two disciplines, one engineering mindset.
I am an Information Systems student with a vocational foundation in computer and network engineering, combining full-stack development with hands-on web application security testing. My work is grounded in systems thinking, practical implementation, and a habit of validating the security of what I build.
Background
My technical foundation began in vocational high school, where I studied Computer and Network Engineering. I ranked first in the National Final Examination and earned a top-score certification from BNSP, which gave me a strong base in subnetting, routing, switching, Linux administration, and structured network thinking before I entered application development.
Since then, most of my learning has happened through building complete systems rather than isolated exercises: a solo-developed payment platform, a team-based national competition project, and a security assessment recognized by my university. I document the real scope of each project, including trade-offs and areas for improvement, because that is more valuable than polished storytelling without substance.
Why security and development belong together
Building web applications taught me where shortcuts appear under deadline pressure. Testing those same systems taught me how exploitable those shortcuts can become. That is why I do not treat development and security as separate lanes; they are complementary parts of the same engineering process.
I am currently in my fifth semester, and I approach my experience honestly: it is self-directed, internship-informed, and project-driven rather than large-scale enterprise production history. What I can bring is a strong technical foundation, a security-first habit, and a track record of finishing work that is useful and demonstrably real.
How I Approach Engineering
Five working principles that show up across every project on this site.
- Build FirstA working prototype with rough edges beats a perfect plan that never ships.
- Test Like An OutsiderOnce a feature works, the next question is how someone would abuse it, applied before external review rather than instead of it.
- Document While BuildingNotes get written during development, not reconstructed afterward, for handoffs and for future me.
- Prefer Boring SolutionsAuditable beats clever, even when the auditable option costs some flexibility.
- Name The GapsGo, Supabase Edge Functions, and formal bug bounty methodology are stated as active learning, not overstated as mastery.
Core Competencies
Organized by depth of real experience, not self-rated percentages.
Primary
Depth: HighFull-Stack Development (MERN)
Designed relational and document-based schemas depending on the shape of the data. Built RESTful APIs with clear separation between routing, controllers, and business logic. Implemented authentication middleware, input validation, and role-based access checks. Built React frontends with state management for real-time updates.
Primary
Depth: HighWeb Application Security (VAPT)
Manual testing methodology for authentication and session handling flaws. Systematic IDOR testing across API endpoints, not only obvious numeric identifiers. Working familiarity with common injection classes, with primary depth in access control. Writing findings developers can act on directly.
Secondary
Depth: WorkingDatabase & Backend-as-a-Service
Working experience with PostgreSQL, Supabase, and Firebase for schema design and backend services outside a pure MongoDB stack, including basic Supabase row-level security policies.
Secondary
Depth: WorkingNetwork Infrastructure
Certified LAN/WAN design, subnetting, and Linux administration, reinforced through a network engineering internship simulating a 4-building corporate site in Cisco Packet Tracer.
Developing
Depth: GrowingProduct & UX Fundamentals
Working knowledge of Figma prototyping, basic WCAG accessibility principles, and user flow mapping, applied directly on the LifeFin project for non-technical end users.
Actively Learning
Depth: NewGo (Golang)
Building recon and automation tooling in Go to support faster bug bounty workflows. Comfortable with basic syntax and goroutines conceptually, not yet claiming production experience.
Proficiency Matrix
Depth of hands-on use measured against real project work, not self-rated enthusiasm. Bars reflect where the hours have actually gone.
Development
Security
Infrastructure & Tooling
Calibration: Advanced (75+) · Working (50–74) · Learning (<50) — measured against shipped work, not time spent reading documentation.
Tech Stack
Tools grouped by category, reflecting actual project use rather than a keyword list.