Security Engineer
Expertise in application security, penetration testing, and security architecture
Capability map · 78 modules
Explore the universe, then scan the actual tools and practices by the production outcome they support.
initializing universe…
How the work connects
The planets are the detail. These three tracks show how those capabilities connect when the work has to ship, stay safe, and be explainable.
$ track --secure
Research, testing, and verification that make risk visible before it becomes production impact.
Find the risky assumption before it ships
Expertise in application security, penetration testing, and security architecture
Identifying and exploiting security vulnerabilities in systems
Participating in and solving Capture The Flag security challenges
Applying OWASP security principles and best practices
Static Application Security Testing to identify vulnerabilities in code
Dynamic Application Security Testing to find runtime vulnerabilities
Securing APIs against common vulnerabilities and attacks
Open Source Intelligence gathering and analysis for security research and threat intelligence
Investigating digital artifacts and recovering evidence for security incident analysis
Understanding network protocols, architecture, and security to identify and mitigate network-based threats
Plugin vulnerability research and exploitation: auditing WordPress plugins, reproducing CVEs and responsible disclosure. Got multiple CVEs and PoCs accepted.
Mapping attack paths, trust boundaries, and failure modes before a system reaches production
Reviewing identity, ownership, permissions, and privilege boundaries in application workflows
Reproducing findings, documenting impact, and coordinating safer remediation with maintainers
Verify from code to live behavior
End-to-end testing of web applications using Playwright automation framework
Browser automation for testing web applications
Combining browser checks, API evidence, logs, and rollback awareness before calling a release ready
$ track --operate
Application development, infrastructure, and data systems that keep a release path understandable.
Product systems with inspectable delivery
Building modern web applications with Node, Express, React, Next.js, and other frameworks
Building scalable backend services and APIs with Node.js runtime
Building user interfaces with React and related libraries
Creating full-stack React applications with Next.js framework
Writing type-safe JavaScript code with TypeScript
Building applications, scripts, and automation tools with Python
Version control and collaborative development using Git
Building and maintaining Laravel application flows, queued jobs, APIs, and production recovery paths
Size, deploy, diagnose, and recover production systems
Configuring and optimizing web servers including Nginx and OpenLiteSpeed (OLS)
Containerizing applications for consistent deployment across environments
Building and maintaining continuous integration and deployment pipelines
Infrastructure as Code for provisioning and managing cloud resources
Managing servers and services across multiple cloud platforms including AWS, Azure, Digital Ocean, and Vultr
Linux system administration and shell scripting
Setting up monitoring and alerting systems for applications and infrastructure
Managing enterprise domain activation, DNS verification, cache, analytics, security events, and edge controls across production sites
Configuring and managing mail servers, SMTP relay, email deliverability, SPF, DKIM, DMARC, and transactional email infrastructure
Making deployments repeatable with build checks, environment awareness, rollback context, and clear handoffs
Using logs, health signals, and failure context to diagnose production symptoms and restore service safely
Designing and operating server lifecycles across cloud providers through a managed hosting control plane
Packaging repeatable application installs, configuration flows, and managed lifecycle operations
Turning Docker Compose and repository-based application requirements into deployable templates
Supporting Node.js application deployment, domain changes, SSL, logs, and operational recovery
Designing observable queued work, retries, status reporting, and recovery for long-running platform tasks
Matching application workloads to practical server CPU, memory, storage, and operational requirements
Provisioning, configuring, re-provisioning, monitoring, and retiring managed server environments
Tracing failed builds, service configuration, logs, networking, and upstream errors to restore a live application
Configuring Nginx and edge-facing routing so applications, domains, SSL, and upstream services connect safely
Integrating private network access and VPN workflows into a managed server platform
Deploying and maintaining owned services from application setup through updates, monitoring, and incident recovery
Data systems and ownership boundaries
Designing, optimizing, and managing relational databases with MySQL
Working with NoSQL databases using MongoDB for flexible, document-oriented data storage
Database administration, optimization, and security across different database systems
Working with backend services, authentication, database workflows, and production-aware operational boundaries
$ track --automate
AI workflows, automation, and human coordination for repeated technical work with clear approval points.
Harness models with tools, context, and boundaries
Integrating models into real technical workflows with bounded inputs, evaluation, and human control
Building intelligent AI bots and virtual assistants using LLMs, conversational AI frameworks, and custom integrations
Coordinating coding agents, tool access, context, and verification without treating autonomy as a substitute for review
Connecting Claude, Codex, and other model runtimes to practical tools and scoped workflows
Structuring instructions, evidence, and task context so model outputs remain useful and inspectable
Coordinating specialized AI agents, scoped responsibilities, and review checkpoints across a larger delivery workflow
Giving AI runtimes controlled access to browser, terminal, search, and application tools through explicit interfaces
Deploying and operating OpenClaw, Hermes, and personal agent bots with scoped tools, observability, and human checkpoints
Designing reusable skills, project memory, and context boundaries so agent work remains consistent over time
Deploying private AI interfaces and model services such as Ollama, Open WebUI, and LibreChat on owned infrastructure
Managing local model availability, pulls, service health, and practical resource constraints for self-hosted LLMs
Automate the repeatable; keep impact reviewable
Designing and orchestrating automated workflows and integrations with n8n for data pipelines and business processes
Designing reviewable LLM workflows for research, development, QA, documentation, and operations
Sequencing agent tasks, approval gates, and handoffs for repeatable technical delivery
Automating repeatable checks while keeping live verification and release decisions visible
Turning delivery context, runbooks, and decisions into maintainable technical documentation
Building persistent terminal workflows that make coding sessions, checks, and recovery steps repeatable
Automating domain verification, certificate workflows, status checks, and recovery-aware updates
Building controlled browser and desktop workflows for repeatable validation and operator-assist tasks
Deploying, updating, and operating workflow tools such as n8n with service-level visibility
Turn real needs into sequenced delivery
Building innovative solutions to solve real-world problems
Understanding financial principles, investment strategies, and economic decision-making
Breaking work into observable milestones, coordinating stakeholders, and keeping delivery moving without losing technical rigor
Explain, coordinate, and decide clearly
Leading teams and projects to successful outcomes
Effectively communicating complex technical concepts
Analytical thinking and creative problem-solving skills
Managing projects, teams, events and resources effectively to achieve organizational goals