> initializing kernel
AAM // BOOT000%

   

Application security engineer. I break software the way attackers would, then help build it back stronger. Pentesting, secure code review, and threat modeling from the dark, glowing edge of the marsh.

   .-~~~~~~~-.
  .~ o o o o ~.
 ( o o o o o o )
(o o o o o o o o)
 ( o o o o o o )
 '~-._______.-~'
     | : : |
     | : : |
     | : : |
   .-| : : |-.
  (___________)

Field Report

[ DESIGNATION ]
AppSec Engineer
[ FOCUS ]
Offensive + Defensive
[ TEAM ]
AppSec
[ STATUS ]
Operational 365

I’m an application security engineer who treats every codebase like an ecosystem. Most bugs aren’t loud; they grow quietly in the dark, in the gaps between trust boundaries. My job is to go in with a light and find them before anyone else does.

I work across the whole lifecycle: adversarial testing of web, mobile, and API surfaces, line-level secure code review, and threat models that bake security into the design instead of bolting it on. I like clear write-ups, reproducible findings, and fixes that actually hold.

Off the clock you’ll find me in CTFs, poking at auth flows, building 3D toys, and collecting good security writing.

Capabilities

01

Penetration Testing

Adversarial assessment of web, mobile, and API surfaces. I find the path attackers would take, then document exactly how to close it.

[ STACK ]
> WEB
> API
> MOBILE
> NETWORK
02

Secure Code Review

Line-level audit of source for injection, broken auth, and logic flaws. Manual depth, backed by static analysis where it earns its place.

[ STACK ]
> SAST
> MANUAL
> CI/CD
03

Threat Modeling

Mapping trust boundaries and abuse cases early, so security is designed into the system rather than bolted on after launch.

[ STACK ]
> STRIDE
> DESIGN
> RISK
04

App Hardening

Turning findings into durable fixes: auth, headers, input handling, and defense-in-depth that survives the next refactor.

[ STACK ]
> REMEDIATION
> DEVSECOPS
05

Vuln Research

Digging into how things actually break, for sport and for signal. Disclosure handled responsibly, every time.

[ STACK ]
> FUZZING
> 0DAY
> CVE
Tooling & Tech
Burp Suite Python Go Semgrep Nuclei Ghidra Snyk Sonatype Checkmarx ArmorCode Edgescan Docker Terraform AWS Kubernetes Frida Claude Codex Cursor Kiro JavaScript

Selected Work

Off the Clock

POD-01● PRODUCT & CRAFT

Lenny's Podcast

with Lenny Rachitsky

World-class product and growth leaders, broken down into tactics you can actually ship.

Spotify ↗
POD-02● TECH & CHAOS

404 Media

by Joseph, Jason, Sam & Emanuel

Journalist-run dispatches from the internet’s weird, broken underbelly: hacking, privacy, surveillance, AI.

Spotify ↗
aam@zangarmarsh:~$ whoami
type 'help' for commands
aam@zangarmarsh:~$