I write the vulnerable code, exploit it, then ship the patch — so your team can see all three. Software engineer first, AppSec by consequence.
Application security engagements — multi-tenant isolation audits and payment integration reviews. Backend, platform and DevSecOps roles, remote or Nairobi. UTC+3.