Comprehensive Android application penetration test, reverse engineering analysis, and vulnerability assessment for a production-ready mobile application.
The Objective:
A mobile application provider required a full-scope security audit to evaluate their client-side attack surface, verify compliance with the OWASP Mobile Application Security Verification Standard (MASVS Level 2), and uncover critical runtime flaws before public deployment.
The Approach:
I executed a hybrid security assessment combining static application security testing (SAST), dynamic instrumentation (DAST), and automated reconnaissance. Every vulnerability was manually validated using tools like Frida, Objection, Jadx-GUI, and Burp Suite to eliminate false positives and scored using standard CVSS 3.1 metrics.
From a single comprehensive audit, I uncovered 19 reproducible findings:
1 High Severity: Insecure local data storage exposing unencrypted user credentials and private API keys in the shared preferences file.
This project focused on building and testing a practical AI security assessment lab for evaluating LLM defenses against prompt injection and jailbreak attacks.
I integrated Spikee by Reversec with a locally hosted cybersecurity model running through LM Studio, then added NVIDIA NeMo Guardrails to compare model behavior under three conditions: no guardrails, input filtering, and combined input/output protection.
The work included configuring the local model environment, building a custom FastAPI gateway, integrating NeMo Guardrails, troubleshooting model latency and timeout issues, creating a reusable Spikee target, and analyzing attack results using Spikee’s built-in reporting tools.
The project also explored different adversarial testing approaches, including prompt injection datasets, obfuscation, encoded attacks, Best-of-N testing, synthetic canary leakage tests, and structured benchmark comparisons.
The objective was to measure how much the guardrails reduced successful attacks while keeping the model, dataset, and testing conditions consistent.
This project demonstrates a hands-on approach to LLM red teaming, AI safety testing, prompt-injection assessment, and guardrail validation for organizations deploying generative AI systems.
𝐏𝐫𝐨𝐣𝐞𝐜𝐭 𝐝𝐞𝐬𝐜𝐫𝐢𝐩𝐭𝐢𝐨𝐧:
I integrated Single Sign-On (SSO) using OpenID Connect into an existing Flask application. I implemented a secure authentication flow with a standard identity provider, enabling seamless and centralized login. I handled token validation, session management, and secure user identity processing. This reduced login friction while maintaining strong security standards, and I delivered a stable, production-ready authentication system within a tight deadline.
FCC (Fortified Central Command) is a cybersecurity mobile application covering Managed XDR, SIEM, Incident Response, Penetration Testing, and Attack Surface Management (ASM). I led the mobile development for this React Native app, taking it from an aging codebase through a major overhaul. That included upgrading React Native from version 0.64 all the way to 0.84, resolving compatibility issues along the way, and optimizing the Android bundle size so the app installed and updated faster.
Beyond the upgrade, I led a team of 3 developers through a full redesign of the app's UI and architecture. We built out core features including 24/7 analyst chat, real-time threat alerts, escalation workflows, and live security dashboards. I also cleaned up the codebase by resolving over 700 SonarQube issues, and kept the app stable through frequent, last-minute backend API changes, which happens a lot in a fast-moving security product like this.
This project really sharpened my skills in large-scale React Native migrations, performance optimization, leading a small team, and building for a high-stakes environment where reliability matters more than almost anything else.