The complete arsenal.
Every discipline, every language, every certification — with context for where they sit in the practice. Security leads.
Where my attention is now. Certified in Cybersecurity (ISC2), and practising web application testing hands-on — Burp Suite and ffuf against the OWASP Top 10, on deliberately vulnerable targets I host myself in Docker.
- Burp Suite
- ffuf
- OWASP Top 10
- JWT / Auth Testing
- SQL Injection
- Linux
- Windows
- Networking
- Docker
The trade I came in through, and still the fastest way I have to understand how an application breaks. Next.js and TypeScript by default, Postgres via Prisma.
- HTML
- CSS
- JavaScript
- TypeScript
- React.js
- Next.js
- Node.js
- Express.js
- PostgreSQL
- Prisma ORM
- Stripe
- Resend
- Sentry
- Upstash (Redis & QStash)
Artificial Intelligence
3 itemsLLM APIs, AI-assisted editors, and open-source agents. Used as leverage on the work — and deliberately kept out of the security challenges I set myself.
- LLM APIs (Gemini, Grok, OpenAI)
- AI-Powered IDEs (Cursor, Windsurf, Claude Code)
- Open-Source AI Agents (OpenClaw, AutoResearch)
Classical stats through modern neural nets. I care about the shape of the data more than chasing the newest model.
- Python
- Linear Models
- MLP
- CNNs
- RNNs
- MDP
- Q-learning
Unity + C#, with a love for pixel art and the patience of iteration that only game feel teaches you.
Solidity + Foundry. Pragmatic: I use the chain when it actually helps, and I stay out of it otherwise.
Java, C, C++, and R alongside the Python, TypeScript, and C# I use daily. I pick the language the problem deserves.
Git, IBM Cloud, Google Cloud, Tableau, Excel. The boring backbone that keeps everything else reproducible.
- Git & GitHub
- IBM Cloud
- Google Cloud
- Tableau
- Excel
- Microsoft Office