This site works best with JavaScript enabled.

Case File 02 — About

Two disciplines, one engineering mindset.

I am an Information Systems student with a vocational foundation in computer and network engineering, combining full-stack development with hands-on web application security testing. My work is grounded in systems thinking, practical implementation, and a habit of validating the security of what I build.

Background

My technical foundation began in vocational high school, where I studied Computer and Network Engineering. I ranked first in the National Final Examination and earned a top-score certification from BNSP, which gave me a strong base in subnetting, routing, switching, Linux administration, and structured network thinking before I entered application development.

Since then, most of my learning has happened through building complete systems rather than isolated exercises: a solo-developed payment platform, a team-based national competition project, and a security assessment recognized by my university. I document the real scope of each project, including trade-offs and areas for improvement, because that is more valuable than polished storytelling without substance.

Why security and development belong together

Building web applications taught me where shortcuts appear under deadline pressure. Testing those same systems taught me how exploitable those shortcuts can become. That is why I do not treat development and security as separate lanes; they are complementary parts of the same engineering process.

I am currently in my fifth semester, and I approach my experience honestly: it is self-directed, internship-informed, and project-driven rather than large-scale enterprise production history. What I can bring is a strong technical foundation, a security-first habit, and a track record of finishing work that is useful and demonstrably real.

Five working principles that show up across every project on this site.

  • Build FirstA working prototype with rough edges beats a perfect plan that never ships.
  • Test Like An OutsiderOnce a feature works, the next question is how someone would abuse it, applied before external review rather than instead of it.
  • Document While BuildingNotes get written during development, not reconstructed afterward, for handoffs and for future me.
  • Prefer Boring SolutionsAuditable beats clever, even when the auditable option costs some flexibility.
  • Name The GapsGo, Supabase Edge Functions, and formal bug bounty methodology are stated as active learning, not overstated as mastery.

Organized by depth of real experience, not self-rated percentages.

Primary

Depth: High

Full-Stack Development (MERN)

Designed relational and document-based schemas depending on the shape of the data. Built RESTful APIs with clear separation between routing, controllers, and business logic. Implemented authentication middleware, input validation, and role-based access checks. Built React frontends with state management for real-time updates.

Primary

Depth: High

Web Application Security (VAPT)

Manual testing methodology for authentication and session handling flaws. Systematic IDOR testing across API endpoints, not only obvious numeric identifiers. Working familiarity with common injection classes, with primary depth in access control. Writing findings developers can act on directly.

Secondary

Depth: Working

Database & Backend-as-a-Service

Working experience with PostgreSQL, Supabase, and Firebase for schema design and backend services outside a pure MongoDB stack, including basic Supabase row-level security policies.

Secondary

Depth: Working

Network Infrastructure

Certified LAN/WAN design, subnetting, and Linux administration, reinforced through a network engineering internship simulating a 4-building corporate site in Cisco Packet Tracer.

Developing

Depth: Growing

Product & UX Fundamentals

Working knowledge of Figma prototyping, basic WCAG accessibility principles, and user flow mapping, applied directly on the LifeFin project for non-technical end users.

Actively Learning

Depth: New

Go (Golang)

Building recon and automation tooling in Go to support faster bug bounty workflows. Comfortable with basic syntax and goroutines conceptually, not yet claiming production experience.

Scope note. Not claiming expertise in automated fuzzing frameworks beyond basic FFUF usage, mobile application security testing, cloud infrastructure security at scale, or binary and reverse engineering. Areas that would need ramp-up time, stated now rather than discovered later.

Depth of hands-on use measured against real project work, not self-rated enthusiasm. Bars reflect where the hours have actually gone.

Development

JavaScript / TypeScriptAdvanced
Node.js / ExpressAdvanced
ReactAdvanced
REST API DesignAdvanced
MongoDBAdvanced
PostgreSQL / SupabaseWorking

Security

IDOR & Access ControlAdvanced
OWASP Top 10Advanced
Authentication BypassWorking
Burp Suite & ToolingWorking
Recon AutomationWorking

Infrastructure & Tooling

Network Engineering (LAN/WAN)Advanced
Linux AdministrationWorking
Bash ScriptingWorking
PythonWorking
Go (Golang)Learning

Calibration: Advanced (75+) · Working (50–74) · Learning (<50) — measured against shipped work, not time spent reading documentation.

Tools grouped by category, reflecting actual project use rather than a keyword list.

Languages

JavaScriptTypeScriptGoPythonBashSQL

Frontend & Design

ReactHTML5CSS3FigmaWCAG

Backend, Database & Cloud

Node.jsExpressMongoDBPostgreSQLSupabaseFirebaseREST API

Security Toolkit

Burp SuiteNmapWiresharkKali LinuxParrot OSOWASP Top 10Cisco Packet Tracer