Security
Security engineering, defense-in-depth, and the attacker's perspective.
Writing on API security, authorization design, penetration testing, and building systems that resist abuse.
Articles
Security writing.
Threat modeling an API before the first endpoint ships
Authorization boundaries, attacker workflows, telemetry, and test cases for secure backend design.
Read article →Writing authorization tests developers will actually maintain
How to turn policy rules into CI-enforced test suites that catch horizontal and vertical privilege escalation.
A methodology for scoped API penetration testing
Recon, enumeration, access control testing, and structured reporting for a single API surface.