🎯 Currently focusing on: Security Operations (SOC), Threat Detection, Incident Response, and Holistic Application Security.
My methodology is rooted in a core engineering principle: "To defend a system effectively, you must first understand how it is built—and how it can be broken."
As a Computer Engineer and SOC Analyst, I focus on bridging the gap between the Software Development Life Cycle (SDLC) and defensive security operations. By actively building complex applications (Microservices, AI, Full-stack), I have mastered the underlying architectures of modern systems. I combine this "builder's mindset" with my offensive security background (Penetration Testing, Vulnerability Analysis) to proactively hunt threats, analyze logs, and strengthen defensive layers via SIEM and the MITRE ATT&CK framework.
- Focus: Security Operations Center (SOC), Cyber Threat Intelligence, Log Analysis, and Application Security.
- Methodology: Merging software engineering roots with offensive insights to create robust, proactive defense strategies.
I utilize a diverse stack to understand the anatomy of modern applications and defend them effectively.
| Domain | Technologies & Architectures |
|---|---|
| Security Competencies | SOC Operations, SIEM, Threat Intelligence, Incident Response, Application Penetration Testing, Secure Code Review |
| Backend & Frameworks | .NET Core, ASP.NET MVC, Django, Flask, Node.js Microservices Architecture, RESTful APIs |
| Languages | Python, C#, C++, C, JavaScript/TypeScript, SQL |
| Data & ORM | MSSQL, PostgreSQL, MongoDB, MySQL SQLAlchemy, Entity Framework, ACID Principles |
| Systems & Cloud | AWS, Docker, Linux (Debian/RedHat), Windows Server, Active Directory |
I develop these projects to deepen my mastery of software architecture, which directly enhances my ability to secure and monitor them.
| Project | Core Stack | Description & Purpose |
|---|---|---|
| AppRay ⭐ | .NET 8 Nuclei MobSF Docker Ollama |
Mobile Security Platform: End-to-end Android security pipeline — SAST (JADX + regex + MITRE CWE) → emulator-based dynamic analysis with mitmproxy traffic capture → DAST (custom Nuclei templates) → AI-assisted unified report. |
| bagchat | ASP.NET Core React MongoDB Docker AD |
Internal Communications: Municipality internal messaging & announcement platform featuring Active Directory integration and a fully containerized architecture. |
| Virtual Accounting Platform | Flask SQLAlchemy RBAC |
B2B SaaS: A comprehensive CRM and accounting platform managing client relations, appointments, and support tickets via custom Role-Based Access Control. |
| Autonomous Waste Sorting | ROS Gazebo C++ |
Robotics Simulation: A "Digital Twin" project using Computer Vision and PID controllers to automate industrial waste separation in Gazebo. |
| LungRisk-AI | Django Python AI/ML |
AI Web Application: A platform developed with Django that uses Machine Learning to analyze clinical data and predict smoking-related health risks. |
| GameRent | .NET 7 MSSQL |
Enterprise Automation: A monolithic management system focusing on strict database integrity (ACID) and layered architecture in .NET. |
| Primefit | PHP MySQL JS |
E-Commerce: A functional fitness store featuring shopping cart logic, session management, and custom frontend design. |
| Student Info System | Python PyQt5 |
Desktop Application: A local tool for student record management focusing on direct database interactions and GUI design. |
| Certification | Issuer | Date |
|---|---|---|
| Siber Vatan Program | Ministry of Industry & Technology · Presidency of Defence Industries | Jun 2026 |
| Certified Web Security Expert (CWSE) | Hackviser | May 2026 |
| Penetration Tester (120 Hours) | CyberExam | Feb 2026 |
| Cyber Threat Intelligence Analyst | CyberExam | Feb 2026 |
| SOC Analyst Level 1 (100 Hours) | CyberExam | Aug 2025 |
| Introduction to Cybersecurity | Cisco | 2025 |
| Pre Security | TryHackMe | 2025 |
| Cyber Security 101 | TryHackMe | 2025 |
