π― Security Researcher | Speaker | Open Source Contributor
-
π Product Security Engineer at Okta (Auth0 Team) β focused on secure software supply chains.
-
π§ Creator of SCAGoat β a vulnerable-by-design application to evaluate SCA tools and supply chain attack detection.
-
π£οΈ Featured Speaker at top-tier security conferences:
-
π§° Regular secure coding trainer, reviewer for security conferences, and CTF enthusiast.
-
π Researching OSS poisoning, model exposure abuse, malicious packages, and DevSecOps automations.
π Featured Project: SCAGoat
A deliberately insecure and compromised SCA testbed that simulates:
- CVE exposure in Node.js and Spring Boot apps
- Malicious/compromised packages
- Reachability and fix validation workflows
Ideal for evaluating SCA tools, container scanners, and CI/CD defenses.
π¬ Letβs connect to talk about research, secure development, OSS risks, or collaborations!