about
I'm Sang Tran, an application security engineer at H-E-B. I find and fix security issues in software, and help build the practices and automation that keep them from coming back.
My approach: make the secure path the easy path. Threat model early, automate the boring checks, and keep findings actionable so engineers fix them instead of filing them.
toolbox
Assessment
Threat modeling (STRIDE)Secure code reviewWeb/API pentestingOWASP ASVS / Top 10
Automation
SAST (Semgrep, CodeQL)DAST / fuzzingSecrets scanningCI/CD security gates
Supply chain
SBOM (CycloneDX/SPDX)SCA & dependency triageSLSA / provenanceArtifact signing
Cloud & platform
AWS / GCP hardeningKubernetes securityIAM least privilegeIaC scanning
Engineering
PythonTypeScriptGoBash