Overview
Technical skills
Timeline
Roles

Overview

Frontend UI engineer (Middle) focusing on polished, accessible interfaces and micro-interactions. The strongest proven skill is building custom, production-ready UI components and interactions with explicit accessibility and UX handling, exemplified by Nutralux/chat-widget.js and the design-token-driven styles in Nutralux/styles.css. There is limited evidence of automated test coverage, large-scale system design, or formal backend/CI engineering practices in public code.
Phone

Technical skills

Languages
8
Python
Node JS
JavaScript
C++
SQL
Go
C
PHP
Node JS
3
Axios
Express
Puppeteer
DevOps
6
GitHub
Git
AWS
GCP
Amazon S3
Netlify
Frontend
3
React.js
Redux Toolkit
Vite
Cybersecurity
4
Metasploit
OWASP Top 10
Active Directory
Burp Suite
Other
20
LLM
Tkinter
Docker
Linux
Windows
Sentry
OpenSSL
Ubuntu
Nessus
Wireshark
Nmap
Kali Linux
TCP/IP
Debian
Hashcat
Acunetix
DNS
VPN
proxychains
OWASP

Timeline

İstanbul Sabahattin Zaim Üniversitesi
Bachelor's Degree • Sotware engineer
2022–2026 Istanbul, Turkey
Security Researcher (Bug Bounty) • Middle
Mozilla • Full-Time
Jun 2026 to Present In office
Researched Mozilla web properties and found evidence of a subdomain takeover risk. Detected a dangling CNAME pointing to an unoccupied Netlify site and validated the issue via response similarity patterns and shared identifiers. Prepared recommendations for remediation in line with domain takeover handling policies.
Netlify
Security Researcher (Bug Bounty) • Middle
OVO (Grab) • Full-Time
Jan 2026 to Present In office
Performed authorized bug bounty research against a large fintech platform. Identified conditions enabling subdomain takeover related to dangling CloudFront mappings to S3 origins and verified affected origins using multiple independent checks. Documented exploitation impact such as credential phishing, malware distribution, session theft, and potential supply-chain XSS, following responsible disclosure practice.
AWS
Amazon S3
Security Researcher (Bug Bounty) • Middle
Banco Plata • Full-Time
Jan 2025 to Jan 2026 1 Year In office
Conducted authorized security testing on public and unauthenticated web/API endpoints. Reported blind SSRF leading to AWS metadata and internal services, uncovered a publicly listed S3 bucket with sensitive documents, and identified information leakage through exposed configuration/secret files. Also documented missing rate limiting and infrastructure exposure from client-side assets and CSP.
AWS
Amazon S3
GCP
Middle Backend Developer Confidence: Medium Generalist
Security-oriented Python developer at a Middle level specializing in implementing small-scale cryptographic protocols and networked tools. The strongest proven skill is applied cryptography and protocol design demonstrated by canonical_json signing and RSA-PSS certificate issuance in common.py together with the MSG1-MSG4 handshake implemented across client1.py and client2.py. Not evidenced are production-grade features such as persistent certificate storage with migration history, automated test coverage and comprehensive observability or deployment hardening.
API Design
4/10
How well APIs are designed
Custom length-prefixed JSON socket protocol and a simple typed message handshake are implemented, but there is no versioning, idempotency strategy or documented error contract beyond simple ok/error payloads.
Evidence
MiniPKI-Python-Certificate-Authority-Secure-Clients/common.py: send_json and recv_json length-prefixed protocol
MiniPKI-Python-Certificate-Authority-Secure-Clients/client1.py: MSG1/MSG2/MSG3/MSG4 handshake messages
MiniPKI-Python-Certificate-Authority-Secure-Clients/ca.py: send_json({'ok': True, 'certificate': cert}) response pattern
Data Layer & Database
1/10
Working with databases
No database or migration history; certificate serials are kept in-memory and there is no persistence, transaction control or schema evolution artifacts.
Evidence
MiniPKI-Python-Certificate-Authority-Secure-Clients/ca.py: in-memory self.serial increment in handle_client
MiniPKI-Python-Certificate-Authority-Secure-Clients/common.py: build_cert_unsigned producing in-memory certificate dicts
Scalability & Performance
2/10
Handling load and speed
Basic concurrency with threads and socket timeouts is present, but no queuing, caching, connection pooling or measured performance work and no rate-limiting or backoff strategies.
Evidence
MiniPKI-Python-Certificate-Authority-Secure-Clients/ca.py: server_loop using threading.Thread per connection and socket.settimeout
MiniPKI-Python-Certificate-Authority-Secure-Clients/client1.py: server socket setup with SO_REUSEADDR and settimeout
MiniPKI-Python-Certificate-Authority-Secure-Clients/client2.py: socket.create_connection with settimeout and explicit socket timeouts
System Architecture
3/10
Overall system structure
Reasonable modular structure for a small educational project with shared crypto utilities and separate CA/client components, but the architecture is small-scale and not designed for production service decomposition or deployment concerns.
Evidence
Project layout: ca.py, client1.py, client2.py and common.py separation in MiniPKI-Python-Certificate-Authority-Secure-Clients
MiniPKI-Python-Certificate-Authority-Secure-Clients/common.py: centralized cryptographic utilities reused by CA and clients
Security & Auth
5/10
Protecting data and access
Clear applied cryptography knowledge is evident - RSA-PSS signing, canonical JSON signing, X25519 key exchange and HKDF-based derivation are used; however there are practical omissions such as lack of authenticated encryption (no MAC/AEAD), insecure in-memory secrets, and no secure key storage or revocation model.
Evidence
MiniPKI-Python-Certificate-Authority-Secure-Clients/common.py: sign_cert and verify_cert using RSA-PSS and canonical_json
MiniPKI-Python-Certificate-Authority-Secure-Clients/common.py: x25519_shared_secret and HKDF-based derive_master_key_km / derive_session_key_ks
MiniPKI-Python-Certificate-Authority-Secure-Clients/common.py: aes_encrypt / aes_decrypt usage for message confidentiality
Reliability & Observability
3/10
Stability and monitoring
Some reliability patterns are present such as timeouts, try/except guards, graceful stop flags and a robust recvn implementation, but there is minimal structured observability, no metrics/alerts, and limited retry/backoff strategies.
Evidence
MiniPKI-Python-Certificate-Authority-Secure-Clients/client2.py: logging.basicConfig usage and try/except around network operations
MiniPKI-Python-Certificate-Authority-Secure-Clients/ca.py: stop_flag for graceful shutdown of server_loop
MiniPKI-Python-Certificate-Authority-Secure-Clients/common.py: recvn implementation handling partial reads
Expertise
Python• Middle
Messaging & Real-time• Middle
Industries
Cybersecurity• Middle
Technologies
PHP
Tkinter
Recommendations
  • Replace unauthenticated AES-CFB with an AEAD mode and add message authentication so handshakes and messages cannot be tampered with.
  • Add persistent certificate storage with an explicit schema and a migration history (database + migration tool) so serials and revocations survive restarts.
  • Introduce unit and integration tests for cryptographic operations and the socket protocol and wire them into CI with pre-commit checks.
  • Improve observability by adding structured logging with correlation ids, timeouts with retries/backoff and basic metrics for connections and handshake failures.
Repositories
The developer's experience in this domain has been verified based on AI analysis of the following repositories:
Middle Frontend Developer Confidence: Medium UI Engineer
Frontend UI engineer (Middle) focusing on polished, accessible interfaces and micro-interactions. The strongest proven skill is building custom, production-ready UI components and interactions with explicit accessibility and UX handling, exemplified by Nutralux/chat-widget.js and the design-token-driven styles in Nutralux/styles.css. There is limited evidence of automated test coverage, large-scale system design, or formal backend/CI engineering practices in public code.
UI Component Architecture
5/10
How interface parts are built
Custom component work and a design token system are present, with a single-file chat widget that is self-contained, but most React UI components are not included so component-system design is partial rather than end-to-end.
Evidence
Nutralux/chat-widget.js: self-contained chat widget building DOM, event handling, focus and ARIA
Nutralux/styles.css: design tokens, typography scale and component-level CSS primitives
marketplace/frontend/buynow-client-fe-section-26-fp/buynowdotcom/src/store/features/productSlice.js: Redux Toolkit slices indicating app-level state boundaries
Responsive & Cross-browser
6/10
Works on all screens and browsers
Responsive techniques are deliberate (clamp, grid, media queries, sticky/positioning) and reduced-motion support is implemented, showing cross-device considerations.
Evidence
Nutralux/styles.css: extensive use of clamp(), CSS grid, media queries and prefers-reduced-motion rules
Nutralux/chat-widget.css: media query for mobile layout and adaptive panel sizing
Performance Optimization
5/10
Speed of the interface
Measured performance artifacts (image preloads, fetchpriority, lazy loading and staged reveal rendering) are present, but no CI performance budgets or bundle-analysis evidence.
Evidence
Nutralux/index.html: <link rel="preload" ... fetchpriority and image loading=lazy/decoding attributes
Nutralux/chat-widget.js: incremental reveal() rendering parts of bot replies to improve perceived responsiveness
Accessibility & Semantics
6/10
Usable for everyone
Accessibility is intentionally considered: ARIA labels, role usage, focus management and keyboard handlers are implemented along with focus-visible styles and reduced-motion respect.
Evidence
Nutralux/index.html: aria-labels across navigation, role="tablist" and other semantic attributes
Nutralux/chat-widget.js: role="dialog", launcher aria-expanded, Escape key to close, focus() after open and accessible toast/status handling
Nutralux/styles.css: :focus-visible styles and @media prefers-reduced-motion rules
State Management & Data Flow
4/10
Managing data in the app
Server-state handling is conventional Redux Toolkit async thunks with basic error handling; the chat widget manages request lifecycle and errors but lacks advanced patterns like cancellation, optimistic rollback or explicit cache invalidation.
Evidence
marketplace/frontend/buynow-client-fe-section-26-fp/buynowdotcom/src/store/features/productSlice.js: createAsyncThunk usages and extraReducers
marketplace/frontend/buynow-client-fe-section-26-fp/buynowdotcom/src/store/features/cartSlice.js: state updates, quantity handling and aggregation logic
Nutralux/chat-widget.js: send() with try/catch, showSteps()/hideSteps() lifecycle and history array for conversation state
UX & Visual Polish
6/10
Look and feel quality
High visual polish and UX details (animations, reveal timing, skeleton/empty/loading states, copy/copy feedback) are well executed and consistent, improving perceived performance and clarity.
Evidence
Nutralux/styles.css: hero, stage, reveal animations, loading-indicator/empty-catalog/error-message CSS
Nutralux/chat-widget.css & chat-widget.js: polished launcher, panel transitions, step indicator and copy feedback
Expertise
React• Middle
HTML & CSS• Middle
Frontend Architecture & Build Tools• Middle
Industries
Commerce• Middle
Health Care• Middle
Technologies
Node JS• Middle
Express
Puppeteer
React.js
Vite
Axios
Redux Toolkit
Recommendations
  • Develop high-impact UI components and experience flows such as chat/support widgets, product galleries and product-detail interactions that require careful accessibility and motion handling.
  • Implement end-to-end tests and component/unit tests (Jest/RTL) and add CI linting/a11y checks to raise engineering maturity.
  • Expand server-state patterns with request cancellation, optimistic updates with rollback, and documented cache-invalidation strategies for complex flows like cart and checkout.
Repositories
The developer's experience in this domain has been verified based on AI analysis of the following repositories:
Middle DevOps Engineer Confidence: High Security Ops
Security engineer focused on practical cybersecurity tooling and applied cryptography with middle-level experience - strongest proven skill is applied cryptography and protocol implementation demonstrated by the MiniPKI common.py certificate build/sign/verify, X25519 key handling, HKDF key derivation and AES encrypt/decrypt functions. The developer shows clear, working end-to-end prototypes for a CA and client key-exchange flow in human-authored code files such as MiniPKI-Python-Certificate-Authority-Secure-Clients/common.py and the GUI clients. There is limited evidence of production hardening, automated tests, CI/CD, infrastructure as code or observability and deployment practices in public code.
CI/CD Pipelines
Automated build and deploy
Not evidenced in public code
Infrastructure as Code
Managing servers with code
Not evidenced in public code
Containerization & Orchestration
Working with containers
Not evidenced in public code
Observability & Monitoring
Watching system health
Not evidenced in public code
Reliability & Incident Response
Keeping systems up
Not evidenced in public code
Cloud & Cost Optimization
Smart use of the cloud
Not evidenced in public code
Industries
Cybersecurity• Middle
Technologies
Python• since 2024 • Middle
Recommendations
  • Develop educational-but-safe PKI proof-of-concepts and security tooling, improving the current MiniPKI into a reusable library with unit tests and API boundaries.
  • Harden cryptographic code for production-readiness: add authenticated encryption (AEAD), explicit error handling, and thorough input validation and test vectors in common.py.
  • Build CI/CD pipelines and automated security tests for the projects, including artifact signing and reproducible builds to raise confidence for reuse.
  • Extend the network tooling into a controlled lab orchestration with repeatable deployments and monitoring so experiments can be run and observed reliably.
Repositories
The developer's experience in this domain has been verified based on AI analysis of the following repositories: