Skip to content
View Sebasalazaro's full-sized avatar
:octocat:
Per Aspera Ad Astra
:octocat:
Per Aspera Ad Astra

Highlights

  • Pro

Block or report Sebasalazaro

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Sebasalazaro/README.md

⚔️ Hi, I'm Sebastian!

Web Application Pentester · Application Security · Full-Stack & Cloud

anime hacking gif


🧠 About me

I’m a Web Application Penetration Tester with a strong background in full-stack software development and cloud infrastructure.

I currently work in a US-based cybersecurity consulting environment, performing security assessments for enterprise and Fortune 500 applications.
Before focusing fully on security, I built and deployed cloud-native web applications end-to-end, which lets me approach pentesting from a developer’s perspective.

Outside of work, I’m into anime, games, and medieval fantasy — I like systems, worlds, and mechanics, whether they’re digital or fictional.


🎯 Current focus

  • 🔐 Web application & API penetration testing (black-box and grey-box)
  • 🧩 Application Security (AppSec mindset)
  • ☁️ Cloud-native architectures (AWS)
  • 🖥️ Thick-client security testing (currently training)
  • ✍️ Writing clear, developer-friendly security reports

🛠️ Technical toolbox

🔒 Security

  • Web application penetration testing
  • Authentication, authorization & business-logic testing
  • Manual request manipulation & vulnerability chaining
  • Burp Suite Professional

💻 Development

  • Python · JavaScript · TypeScript · C · C#
  • FastAPI · React · REST APIs

☁️ Cloud & DevOps

  • AWS (ECS/Fargate, EC2, S3, DynamoDB, IAM, VPC, CloudWatch)
  • Docker · CI/CD (GitHub Actions)

🏗️ Projects worth checking out

(Some repositories are still WIP or private — more coming soon)

  • 🔒 Secure Web App Reference

    • Cloud-native web application built with security-by-design principles
    • Authentication, RBAC, logging, rate-limiting, and CI security checks
  • ⚙️ AppSec CI/CD Pipeline

    • GitHub Actions pipeline with SAST, dependency scanning, and container security
  • 🧠 Security Notes & Write-ups

    • Personal notes on web security testing, AppSec concepts, and real-world findings

📊 GitHub activity


🔗 Find me here


“Security is about understanding systems — sometimes you need to explore the dungeon to find the flaw in the castle walls.”

Pinned Loading

  1. SaSa SaSa Public

    🌱 Fight food waste, save money, help communities — A full-stack marketplace connecting businesses with surplus food to conscious consumers and charitable organizations

    JavaScript 1

  2. QuitoTactico/DnD-AI QuitoTactico/DnD-AI Public

    Project for the Integrated Project 1 course at EAFIT. Dungeons & Dragons game generator

    Python 19 4

  3. vaalmo/chatbot-cf vaalmo/chatbot-cf Public

    Solución de chat automatizado para línea de atención de Whatsapp de Casa Ferretera

    JavaScript 1

  4. Youngermaster/Poneglyph-Reduce Youngermaster/Poneglyph-Reduce Public

    A minimal-yet-real MapReduce system inspired by Hadoop/Spark and designed to satisfy the GridMR assignment requirements

    Java 2

  5. Youngermaster/Weatheria Youngermaster/Weatheria Public

    A Hadoop MapReduce System for Medellín Temperature Analysis (2022-2024)

    Shell 2