Real-Time Video Detection for CAN Bus Fuzzing
hardware · Pairs a live video-detection model with CAN-bus fuzzing to catch automotive faults traditional fuzzers miss, a cyber-physical technique that generalises to any sensor-driven system.
MSc Cyber Security and independent security researcher on the leading bug-bounty platforms. I secure systems end to end, hardware, malware, web, cloud and compliance, and move fast by putting AI, LLMs and cloud tooling to work.
I'm a cyber security engineer who likes building things as much as breaking them. My core is programming, problem solving and security. I write code that actually ships, I pull hard problems apart until they make sense, and I think about how a system breaks before someone else does. That spans offensive work, blue team, cloud and software engineering, and these days I run my own independent security research on HackerOne, Bugcrowd and Intigriti, turning findings into validated, high impact reports.
On the job I've covered a lot of ground. At Oracle I was a software engineer on the Foreign System Interfaces team, leading code reviews and security assessments across clinical products like Millennium, PharmNet, RadNet and PowerChart. I was the L3 escalation point and subject matter expert for high priority clients, closing out 80+ complex code and interface failures, and I led a team of seven system engineers and two solution analysts, running knowledge transfer sessions and writing the incident playbooks we leaned on. Before that I was a cloud engineer at GE, rotating through DevOps, cloud and shift left security, and a security analyst at mDrift Technologies, where I ran OWASP Top 10 assessments and hardened endpoints for a startup.
A few things I'm proud of: an MSc in Cyber Security from the University of Birmingham on a Northrop Grumman merit scholarship, one of seven awarded; a research paper I presented at escar Europe 2025 in Frankfurt to CISOs and CTOs from global automotive OEMs; and recognition at Oracle from managers, executives and clients under their Commit, Deliver, Engage and Collaborate values.
On paper I hold CEH v13, CompTIA Security+, AWS Security, Blue Team Junior Analyst, Qualys VMDR and ISO 21434 automotive cyber security, with a handful of OSINT, network analysis and cloud foundations certs behind them.
However I get there, I lean on AI and LLMs to move fast: LLM assisted triage, cloud scale scanning, automation first tooling. Less time on the repetitive parts, more on the calls that genuinely need a human who understands the threat.
hardware · Pairs a live video-detection model with CAN-bus fuzzing to catch automotive faults traditional fuzzers miss, a cyber-physical technique that generalises to any sensor-driven system.
malware · Reverses an AES-CBC ransomware payload in Python and rebuilds the locked files into a clean directory, malware analysis turned into a working recovery utility.
firmware · Reverse-engineers UART and SPI on a Pico-based security token, then rehosts a key firmware routine with the Unicorn engine to run and analyse it entirely off-device.
web · iot · Full pentest of a consumer smart doorbell, mapping the web and network attack surface and documenting data-exposure and encryption weaknesses in a formal report.
compliance · cloud · Orchestrates OWASP ZAP and Nmap into one automated audit, cookie analysis, third-party script detection and scanning that scales across a whole estate, not one page at a time.
ai-security · Building a static + dynamic scanner that audits Model Context Protocol servers, the fastest-growing AI attack surface of 2026, with 40+ CVEs disclosed in four months. It fuzzes live MCP servers for tool-poisoning, prompt-injection, auth-bypass, and path-traversal flaws, then grades each finding with reproducible proof-of-concept requests.
blue-team · Building an LLM-assisted detection-as-code pipeline that turns a raw threat-intel report into a validated, ATT&CK-mapped Sigma rule with an automated test, compressing intel-to-deployment from days to minutes. Every rule is generated, converted to SIEM queries, sandbox-validated against an Atomic Red Team test, and opened as a pull request, so it's proven to fire before it merges.
cloud · Building a one-command mesh of cloud honeypots and AWS canary tokens that lures attackers and fires a CloudTrail alert the instant a planted credential is used. An LLM classifies each attacker session into TTPs and streams a near-zero-false-positive threat-intel feed to a live attack map.