[ About ]

A developer who thinks like a security specialist.

12+ years building and securing web applications — from lean sites for small businesses to complex, enterprise-grade systems. Solid engineering fundamentals with a security-first mindset, so what gets built is fast, functional and resilient.

Security is not a layer I bolt on

Most web developers meet security as a checklist near the end of a project. My route in was different: alongside application work I did frontend development for a network security and firewall company, which meant living inside the tooling — Suricata IDS/IPS, Microsoft 365 Security, Microsoft Defender and web filtering.

That gave me hands-on exposure to how security is engineered at the infrastructure level, not just the application layer. The practical result is that I design web applications to be secure from the interface down to the network, rather than hardening them after something has already gone wrong.

It is also why the rescue work on this site — malware removal, hardening, incident cleanup — is not a sideline. It is the same skill set pointed at a problem that has already happened.

What I actually work with

Web development

PHPLaravelCodeIgniterWordPressMySQLJavaScriptjQueryAngularNode.jsMEAN stackHTML5 / CSS3

Security

WordPress & web app hardeningMalware removal & remediationGoogle blacklist / Safe Browsing removalBlocklist delisting & reinstatementSuricata IDS/IPSMicrosoft 365 SecurityMicrosoft DefenderWeb filtering

APIs & integration

REST API designGraphQLThird-party API integrationWebhooksToken & OAuth authenticationAPI versioning & documentation

AI & automation

FastAPI backendsAI-driven featuresIntelligent workflow automation

DevOps & CI/CD

GitHub ActionsAutomated deployment pipelinesAI-assisted workflows

Cloud & servers

AWS EC2AWS S3AWS Secrets ManagerLinuxApacheNginxWHM / cPanelPlesk

Databases & data

MySQLMongoDBDatabase design & normalizationIndexing & query optimizationSchema migrationsphpMyAdminBackup & restore strategy

Infrastructure

DNS & domain managementWebsite migrationsSSL/TLS certificatesHosting control panels

Where I go deepest

How I work

  • Scope and price agreed in writing before anything starts. No hourly creep, and no invoice you have not already approved.
  • You own everything. Code lives in your repository, infrastructure is written down, and the handover includes documentation your next engineer can follow.
  • I tell you when the answer is no. If a rewrite is not worth it, or your budget will not cover the job properly, you hear that before you pay rather than halfway through.
  • Reversible by default. Canary rollouts, tested backups and written rollback plans. Nothing consequential happens without a way back.

Who I like working with

Startups, founders and creative teams building something meaningful — people who want a developer close enough to the problem to argue with them about it, not a supplier who ships whatever the ticket says.

I am based in India and work remotely with clients anywhere in the world. Everything runs in English and in writing by default, so there is always a record of what was agreed. Urgent work — a compromised site, a production outage — gets a same-day response whatever your time zone.

Why fixed scope, not hourly

Hourly billing rewards the wrong things. It pays more for slow work, punishes the engineer who solves a problem in one line, and leaves you unable to budget.

Fixed scope forces both of us to be clear about what is being built before anyone starts — the part most projects skip. It also puts the risk of the work running long on me, which is where it belongs.

[ Let's talk ]

Building new, or fixing old?

Either way, describe it in a few lines. You'll get a straight answer on whether I can help, roughly what it would cost, and how long it would take.