Development · Assessment · Security · Automation

Bridging the gap between security and development.

I help teams ship with confidence through practical application security, secure architecture, and automation that fits the way modern developers already work.

Try webscan.dev (external site) Explore the work

  • AppSec
  • DevSecOps
  • Web security
  • Tooling

DEVAesia services

Security and development solutions

Clear deliverables, pragmatic recommendations, and work that fits the way your team ships.

  • Development

    Secure software engineering with useful controls, readable systems, and safe defaults built in from the start.

  • Assessment

    Practical security reviews and vulnerability assessment for web applications, APIs, and delivery pipelines.

  • Analysis

    Technical research that turns noisy signals and uncertain findings into clear, prioritized action.

  • Awareness

    Developer-friendly security enablement grounded in real workflows, useful examples, and shared understanding.

  • Intelligence

    Security posture insights and monitoring guidance for modern applications and their supporting systems.

  • Automation

    CI/CD checks and guardrails that catch meaningful issues early while keeping releases moving.

Featured projects

Tools, publishing, and experiments

Work shaped around readable systems, useful evidence, and security that serves the people building the product.

tool

webscan.dev

A privacy-minded web security scanner designed to turn quick posture signals into useful next steps.

  • Web security
  • Assessment
  • Developer tooling
View project

writing

Techsplicer

Developer-focused cybersecurity analysis and practical guidance.

  • Writing
  • Cybersecurity
  • Research
View project

View every project

How the work moves

Release loop

  1. Plan

    Agree on the problem, the boundaries, the risks, and what a useful result looks like.

  2. Code & Build

    Create the smallest maintainable solution with security and accessibility in its foundations.

  3. Test & Release

    Exercise the real paths, verify the artifact, and make release evidence easy to review.

  4. Deploy & Monitor

    Ship predictably, verify production, and use focused signals to guide the next improvement.

Recent writing

Notes and articles

Latest from Techsplicer

Build-time snapshots from the cybersecurity archive at alexmacra.com.

Explore all writing

Frequently asked questions

A few useful answers

The short version of how assessments, automation, and delivery work.

What security assessment services do you offer?

Vulnerability assessments, targeted penetration tests, secure architecture reviews, API testing, and pragmatic hardening guidance. The focus is on validated issues with clear remediation.

How does your security automation work?

I integrate focused checks into CI/CD and developer workflows, including dependency signals, configuration checks, baseline scanning, and guardrails that reduce regressions.

How does webscan.dev help?

webscan.dev provides quick, non-intrusive posture signals around areas such as TLS, headers, and public files. Deeper testing pairs those signals with a scoped manual assessment.

Do you offer custom security solutions?

Yes. I can build custom checks, internal tools, and automation around a specific stack, particularly when an off-the-shelf product does not fit the delivery workflow.

Can you work with an existing development workflow?

Yes. The aim is to work with the tools and release process already in place so that security findings remain understandable, actionable, and maintainable.

Get in touch

Bring the difficult part.

Tell me what you are building, what is uncertain, and what a useful outcome would look like.

Good starting points

  • Targeted penetration test or AppSec review
  • Secure headers and TLS hardening
  • CI/CD security automation
Email mail@devaesia.com