Defender by day,
disassembler by night.
I spend my days building security that holds up—audit, compliance, risk management. And my evenings figuring out how it breaks, one binary and one packet at a time. The two feed each other: you only defend well what you've learned to attack.
Two hats, one goal
On the offensive side: reverse engineering, binary exploitation and CTF challenges to keep my hands dirty and my eye sharp. It's my training ground—the place where breaking everything is allowed.
On the defensive side: governance, risk and compliance. I translate real threats into verifiable controls—NIS2, CyFun, ISO 27001 frameworks—and build dashboards that speak to technical teams and leadership alike.
This site is my public notebook: writeups, reverse engineering notes, and thoughts on the bridge between technical discovery and business risk.
Where I've put my hours
Indicative bars—the point isn't the score, it's to keep learning.
The path, in plain text
Bridging offense ↔ compliance
I connect my technical findings to security frameworks, and build audit dashboards that read just as well in the field as in the boardroom.
CTF & reverse immersion
Regular CTF play (pwn, rev, web). The best way I know to stay technical in a career that keeps drifting toward management.
GRC & security audit
Scoping security programs, running maturity assessments and preparing for emerging regulatory requirements.
Curiosity, first
It all started with wanting to understand what happens beneath the click. It never really stopped.
One red line, and only one
Everything published here is done on CTF targets, throwaway labs or systems I have explicit authorization for. You don't learn the craft at someone else's expense. Maximum curiosity, strict legal scope.