Security Engineer. I break web apps, APIs, and cloud, then build the tooling and controls so it does not happen twice. Application Security by day; I ship security tools and send fixes upstream on the side.
LinkedIn · X · Portfolio · CV · phinehastettehnarh@gmail.com
Security fixes and detectors sent upstream to projects I use.
| Project | Contribution | Status |
|---|---|---|
| NVIDIA / garak | Unicode normalisation for the StringDetector, on NVIDIA's LLM vulnerability scanner | Merged |
| mlrun | Fixed a tar-slip path traversal in clone_tgz() archive extraction |
Merged |
| canonical / cloud-init | Type annotations for distros.parsers.hosts |
Merged |
| checkov | New policy CKV_AWS_394 for public Secrets Manager secrets | In review |
| gitleaks | Detection rules for Groq and xAI API keys | In review |
| trufflehog | Cerebras API key detector | In review |
| Area | Stack |
|---|---|
| Languages | Python, C#, Go, Bash |
| Offensive | Burp Suite, Metasploit, Nmap, Nessus, Nuclei, Wireshark, Kali Linux |
| AppSec & DevSecOps | SonarQube, Trivy, Checkov, Gitleaks, OWASP Top 10, Docker, Kubernetes, GitHub Actions, nginx |
| Cloud | AWS, Azure, Google Cloud, Microsoft Defender, Zscaler |
| Detection & DFIR | MITRE ATT&CK, threat hunting, threat intelligence, incident response, digital forensics |
| Governance | ISO 27001/27701, PCI-DSS, NIST 800-53, CIS Benchmarks |
A shell script is a bash script, but a bash script is not necessarily a shell script.



