Application security
Application security architecture, Secure SDLC practices, security requirements, technical reviews, preventive controls, security testing and integration of security throughout the development lifecycle.
Architecture · Cybersecurity · Governance
I connect architecture, software development and security governance to turn cybersecurity requirements into technical decisions that are practical, applicable and sustainable.
I specialize in application security, vulnerability management and security governance, and my background also includes previous experience in full-stack software development. This dual perspective enables me to approach security from the standpoint of code as well as architecture, risk and the organization.
Expertise
My approach does not artificially separate strategy, architecture and implementation. Security must be understandable by management, actionable by technical teams and verifiable in real systems.
Application security architecture, Secure SDLC practices, security requirements, technical reviews, preventive controls, security testing and integration of security throughout the development lifecycle.
Vulnerability governance, risk-based prioritization, technical analysis, remediation tracking and alignment between technical exposure, business criticality and compensating controls.
Policies, standards, architecture principles, security requirements, risk management, control models and decision support in complex organizational environments.
Solution analysis, risk modelling, control definition, architecture reviews and support for teams so that security is built in by design.
My full-stack development experience remains central to my practice. It allows me to understand developers' constraints, the internal mechanics of applications and the real consequences of architecture choices.
University teaching, technical communication, development of specialized content and support for professionals who need to integrate cybersecurity into their practice.
Professional background
I began my career in information technology as a software developer. That experience gave me a practical understanding of systems, code, data and the trade-offs involved in delivering digital solutions.
My career gradually specialized in cybersecurity, particularly application security. I then broadened my practice to architecture, vulnerability management, security governance and the integration of security controls into organizational processes.
Today, I work as a cybersecurity architect and advisor with a full-stack perspective: understanding technology deeply enough to get to the root of a problem while maintaining the broader perspective required to address risk, governance and long-term sustainability.
Education
Research Master's degree
Thesis focused on the use of unit testing as a method to prevent SQL injection. The research covers, among other areas, the automation of code-level security controls and the detection of vulnerable behaviour before production deployment.
Bachelor's degree
Foundations in software development, systems, data and computer engineering that later supported a specialization in cybersecurity.
University teaching
I teach cybersecurity at the university and professional levels, with particular attention to the technical mechanisms that explain vulnerabilities rather than the simple memorization of controls.
My teaching topics include application security, SQL injection, applied cryptography, vulnerability analysis, systems security, secure development and security assessment methods.
Teaching complements my professional practice: explaining a security problem clearly requires understanding its causes, limitations and consequences.
Maple production
Alongside my technology career, I am developing an activity as a maple producer. This project is a deliberate return to concrete, seasonal work directly connected to the land.
Maple production requires another form of discipline: observing and understanding a living system, intervening with restraint and accepting that some variables cannot be fully controlled.
At first glance, maple production and cybersecurity belong to two very different worlds. Yet they share one essential principle: resilience depends on the quality of the ecosystem as a whole.
My practice
Cybersecurity goes beyond a collection of tools or policies. It is about understanding what must be protected, why, and how to provide protection that is both effective and sustainable.