~/sang

about

I'm Sang Tran, an application security engineer at H-E-B. I find and fix security issues in software, and help build the practices and automation that keep them from coming back.

My approach: make the secure path the easy path. Threat model early, automate the boring checks, and keep findings actionable so engineers fix them instead of filing them.

toolbox

Assessment

Threat modeling (STRIDE)Secure code reviewWeb/API pentestingOWASP ASVS / Top 10

Automation

SAST (Semgrep, CodeQL)DAST / fuzzingSecrets scanningCI/CD security gates

Supply chain

SBOM (CycloneDX/SPDX)SCA & dependency triageSLSA / provenanceArtifact signing

Cloud & platform

AWS / GCP hardeningKubernetes securityIAM least privilegeIaC scanning

Engineering

PythonTypeScriptGoBash

guest@sang:~$