Skip to main content

Updated October 2026

Now

What I'm working on this month. Application Security Engineer in Charleston, SC, with 5+ years of software engineering behind me.

Working on

  • Passed GIAC GCIH (SEC504) in August 2026. The labs are published here: live PowerShell investigation, RITA beacon detection, Hayabusa log triage, and Nmap discovery.
  • PortSwigger BSCP prep. Web pentesting is a skill I keep sharp, not my identity.
  • Building llm-audit. Twelve OWASP LLM Top 10 rules shipped, more coming for the TS/JS ecosystem Semgrep's official AI pack does not cover.
  • Studying for AWS Security Specialty (SCS-C03, target Q1 2027). IAM least-privilege, CloudTrail detection, and Cognito hardening against enumeration.

Certifications

GIAC GCIH (SEC504)PassedAug 2026
GIAC GSECPassedApr 2026
GIAC GFACTPassedJan 2026
AWS Security Specialty (SCS-C03)In progressTarget Q1 2027
PortSwigger BSCPIn progressTarget Q4 2026
TryHackMe AI Security (AI1)PlannedLate 2026
HackTheBox AI Red Teamer pathPlanned2027
TCM PWPA (Web Pentest)Planned2027

Open to

Senior Application Security, Senior Product Security, and AI Security roles. Remote. I reply within 24 hours to recruiters and hiring managers.

Now. What I'm working on | Luis Javier Lozoya