$ whoami

Full-stack engineer, hardening into application security.

Several years building production web apps — now going deep on AppSec: SAST/SCA tooling, secure pipelines, and cloud security fundamentals, through hands-on projects rather than theory alone.

$ whoami
> Deepesh Dang
> role: Full-Stack Engineer → Application Security
> focus: SAST · SCA · DAST · secrets/container scanning · CI/CD security gates · threat modeling
> goal: AppSec Engineer / DevSecOps / Product Security role
$ status
$ ls skills/

Skills

AppSec & Security Tooling

Semgrep (SAST)Snyk (SCA)npm audit (SCA)OWASP ZAP (DAST)Burp SuiteSplunk (SIEM)Threat modeling

Cloud & DevSecOps

GitHub Actions / CI-CDGCP IAM & Secret ManagerTerraformAWS (ECS, VPC, RDS)

Full-Stack & Frontend

Next.jsReact / TypeScriptJavaScriptPythonJava / Spring Boot
core / hands-onactively building depth
$ git log --oneline --graph

Journey

2026
job-search: targeting AppSec / DevSecOps roles
Actively interviewing, sharpening AppSec fundamentals daily, and building this portfolio and vigilant-engine as evidence of hands-on capability.
Jan 2022 – Aug 2026
Gumtree — Senior Full-Stack Engineer & Application Security Engineer↗
Security champion on a team that didn't own the codebase alone: rolled out Semgrep, gitleaks and npm audit as scanning plus a preventative gate for new code; moved secrets out of application code into GCP Secret Manager with least-privilege scoping; built a Claude Code security-review skill for AI-augmented scanning before merge; integrated Playwright with OWASP ZAP for DAST coverage; and used DangerJS to enforce the security checklist on every PR, failing the build on high-severity ZAP findings. Zero high-severity incidents through 30%+ traffic growth, a 22% defect reduction and ~40% faster delivery.
CSP · SAST · secrets mgmt · DAST gate
2026
build(vigilant-engine): AppSec findings pipeline
Semgrep, Snyk and npm audit run against OWASP Juice Shop; findings normalized into one schema and surfaced on a live dashboard.
SAST · SCA · dashboards
2025–2026
learn: hands-on application security
Started building toward AppSec deliberately — scanner tooling, cloud security fundamentals, and infrastructure-as-code, on top of existing full-stack experience.
Started career in software engineering
Built the full-stack and frontend foundation everything since has grown from.
$ cat goals.md

Where I want to be

19 years in software engineering, now focused on Application Security and DevSecOps: hands-on with SAST, DAST, SCA, secrets and container scanning, CI/CD security gates, SIEM-based findings centralisation and STRIDE threat modelling, with production experience triaging and remediating vulnerabilities at scale. Seeking a dedicated Application Security / Product Security / DevSecOps role.

AppSec EngineerDevSecOpsProduct Security
$ gh repo list

Projects

bulkhead

Tenant-isolation-as-code: a FastAPI demo with a reusable authz layer enforcing row-level tenant scoping, plus a fuzzer that attacks every route for cross-tenant IDOR and fails CI on leaks.

FastAPIIDORauthzearly stage
View on GitHub →
perimeterWatch

A Python cloud-config auditing toolkit: checks S3 buckets and security groups against security baselines and reports findings in a common schema, with CI running pytest, bandit and pip-audit.

Pythonboto3S3bandit
View on GitHub →
+ more

The full list, including work-in-progress repos, lives on GitHub.

View full profile →
$ curl medium.com/@deepeshdang/feed

Articles

DRAFT — COMING SOON

What SAST actually catches (and what it misses)

DRAFT — COMING SOON

Building vigilant-engine: normalizing three scanners into one schema

PLANNED

Frontend engineer's field notes on AppSec

Feed wires up to Medium once the first article publishes.