Palo Alto / Hybrid
Critical SAML authentication bypass
Collaborated with AppSec Lead David Downs to audit backend Django code. Identified a custom certificate check that omitted cryptographic signature verification, enabling forged SAML assertions. Co-authored the vulnerability report, built proof-of-concept exploits, and validated the production patch with python-saml’s process_response() engine in staging.
Enterprise subdomain and DNS automation
Architected a 50-thread Python scanner covering 1,600+ Route 53 domains in under three minutes. Built a five-stage pipeline spanning DNS resolution, IP classification, TLS handshake, HTTP status, and three-layer fingerprinting against 7,500+ AWS S3, Heroku, Azure, and GitHub Pages signatures.
Risk scoring and reporting
Eliminated false positives, scored severity from 0–100, and produced HTML, CSV, Excel, and JSON reporting for repeatable monthly delta scans.
Clinical AppSec
Used Burp Suite to audit clinical workflows, map REST APIs, and evaluate access-control models protecting sensitive patient data.
Technical stack
Python, Burp Suite Professional, SAML 2.0 / SSO, Django, AWS Route 53, asynchronous programming, multithreading, REST APIs, OX Security, and threat modeling.
