Backend Software Engineer extending into offensive security. Six years building and securing production SaaS in PHP, AWS, and Linux — now applying the same systems-level rigor to attack surfaces. OSCP+ in preparation; top 3% on TryHackMe.
Background
Backend Software Engineer at iProtectU, 2020–2026. End-to-end ownership of backend services, REST APIs, and AWS infrastructure for a multi-tenant SaaS platform — 100+ customer environments and 100+ EC2 instances under CI/CD. 90%+ performance gains on critical backend processes; legacy systems refactored into modern OOP/MVC architecture.
Zend Certified PHP Engineer. Certificate of Cloud Security Knowledge (CCSK v4). BCS Level 4 Diploma in Software Development Methodologies. BSc Geography, University of Plymouth.
Evidence
- 15+ unit-tested offensive tools — Bash and Python enumeration and triage scripts, each paired with its own test harness. offsec-scripts.
- A penetration-testing methodology vault — 26+ Linux and Windows privilege-escalation techniques, 4+ exploit walkthroughs, and a full web-application testing workflow. offsec-playbooks.
- OWASP-mapped AppSec case studies — each with a vulnerable-baseline branch and a regression-tested remediation. appsec-lab.
- Top 3% on TryHackMe — 144 rooms completed, rank 0xA. Profile.
The full catalogue — every artifact, the CTF write-ups, and certifications — is on the Portfolio page.