Skip to content
Security Notes

Author

About

By profession, I am a security engineer. I spend most of my days thinking about how systems break, how attackers think, and how we can build software that is harder to exploit. Over the years, I have worked across application security, penetration testing, and product security, helping teams find and fix vulnerabilities before they become real problems.

While this blog is centered on security, my life is not. Outside of work, I am a dog parent, a sports enthusiast, and someone who likes being outdoors whenever possible. You will probably find me snowboarding in the mountains, trying to surf whenever I am near the ocean, or passionately watching cricket. I am also a big movie person and enjoy the occasional deep dive into pop culture.

I also genuinely enjoy cooking. I love experimenting with food from different parts of the world and recreating dishes that remind me of home or places I have visited. For me, cooking and security have something in common. Both require curiosity, patience, and a willingness to experiment.

The goal of this blog is simple. Security often feels more complicated than it needs to be. There are too many buzzwords, too many acronyms, and too many explanations that assume everyone already knows the basics. I want to make the space easier to understand by breaking down complex topics into clear, practical explanations.

You will find a mix of content here, from offensive security and application security to AI security and the occasional thought piece. If something here helps you understand security a little better, then this blog has done its job.

Focus

  • Application and API security reviews
  • AI and LLM abuse cases and safety boundaries
  • Threat modeling that survives contact with engineering
  • Secure design tradeoffs you can explain to product

New essays land here first. No engagement tricks, just writing.

Start with the archive →