Hands-on security work, outside the day job.
Two ongoing projects that push from systems integration into offensive and defensive security practice.
Build, Secure, and Protect a Web Application
A cloud application hosting a personal cyber blog, built and hardened end-to-end on Microsoft Azure — covering cloud architecture, networking, cryptography, and network security.
- Built an Azure Web App and deployed a container to it, with a custom application design.
- Secured the app with a Key Vault; created and analyzed a self-signed certificate against a trusted one.
- Protected the app with a Web Application Firewall — configured custom rule sets and remediated Security Center recommendations.
Exploit Vulnerabilities — Web App, Linux & Windows Servers (CTF)
A capture-the-flag exercise attacking a fictional organization across three tiers: its web application, Linux servers, and Windows servers.
- Web app: applied offensive security techniques to identify and exploit vulnerabilities and capture flags.
- Linux servers: used Nessus for network/vulnerability scanning and Metasploit to gain access and retrieve flags.
- Windows servers: used Nmap for reconnaissance to find open ports and services, then gained access to capture flags.
Systems integration, at scale
Outside of formal security projects, day-to-day work is its own kind of applied systems security: designing and integrating CCTV, access control, intercom, and PA/CIS systems across active NYC Transit stations and depots, and standing up enterprise networks with redundant backbones. See the resume for the full project list.