Skip to content
View y3rb1t4's full-sized avatar
πŸ’­
πŸ§‰
πŸ’­
πŸ§‰

Organizations

@Bondiola-PyteScript @BugBounty-Collab

Block or report y3rb1t4

Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
y3rb1t4/README.md

πŸ›‘οΈ Hi there, Gabo Rodriguez

Typing SVG

πŸ” About Me

I'm a passionate Application Security Engineer dedicated to shifting security left and building a robust DevSecOps culture. I believe security should be everyone's responsibility, not just a checkpoint at the end of the development cycle.

class AppSecEngineer:
    def __init__(self):
        self.name = "y3rb1t4"
        self.role = "Application Security Engineer"
        self.philosophy = "Security as Code, Security by Design"
        self.languages = ["en", "es"]
        self.current_focus = "Integrating security into every phase of SDLC"

🎯 What I Do

πŸš€ DevSecOps Implementation

  • CI/CD Security Integration: Automating security scanning in Azure DevOps pipelines
  • SAST/DAST Automation: Implementing Semgrep, Trivy, and custom security checks
  • Container Security: Vulnerability scanning and runtime protection
  • Infrastructure as Code Security: Terraform/CloudFormation security analysis

πŸ” Security Testing & Research

  • Penetration Testing: Web, Mobile, and API security assessments
  • Vulnerability Research: CVE discovery and responsible disclosure
  • Mobile Security: Android app analysis with Frida and reverse engineering
  • Network Reconnaissance: Infrastructure mapping and attack surface analysis

πŸ“š DevSecOps Evangelism

  • Promoting security awareness across development teams
  • Creating security champions within organizations
  • Building security guardrails that enable, not block, development
  • Mentoring developers on secure coding practices

πŸ› οΈ Security Arsenal

Core Security Tools

Burp Suite OWASP ZAP Metasploit Nmap

SAST/DAST & Scanning

Semgrep Trivy SonarQube Snyk

Mobile Security

Frida MobSF Jadx

Infrastructure & Cloud Security

Docker Kubernetes Azure Terraform

Development & Automation

Python Bash Go Git

πŸ† Security Achievements

  • 🚩 CTF Enthusiast: Regular participant in security CTF competitions
  • πŸ” Bug Hunter: Identified and reported critical vulnerabilities in production systems
  • πŸ“œ Security Automation: Developed custom security scanning frameworks
  • πŸ›‘οΈ Zero Trust Advocate: Implementing zero-trust architectures in enterprise environments

πŸ“Š DevSecOps Metrics That Matter

security_metrics:
  mean_time_to_remediation: "< 48 hours for critical vulnerabilities"
  false_positive_rate: "< 5% through intelligent filtering"
  security_coverage: "100% of production deployments scanned"
  developer_satisfaction: "Security tools that developers actually want to use"

🌟 Current Focus Areas

  • πŸ€– AI-Powered Security: Leveraging ML for threat detection and response
  • πŸ”„ Supply Chain Security: Implementing SBOM and dependency scanning
  • πŸ—οΈ Security as Code: Infrastructure and policy automation
  • πŸ“± Mobile AppSec: Android/iOS security testing automation
  • 🌐 API Security: Building robust API security testing frameworks

πŸ’‘ DevSecOps Philosophy

"The best security is the one that's built-in, not bolted-on. Make security invisible, automatic, and enabling."

My DevSecOps Principles:

  1. Shift Left, But Not Too Far: Security should enable, not obstruct development
  2. Automate Everything: If it can be automated, it should be
  3. Measure What Matters: Focus on metrics that drive real security improvements
  4. Culture Over Tools: Tools don't fix security, people do
  5. Continuous Learning: The threat landscape evolves, so should we

πŸ“ˆ GitHub Stats

GitHub Stats

GitHub Streak

πŸ”— Let's Connect

LinkedIn Twitter Blog

πŸ’¬ Let's Talk Security

I'm always excited to discuss:

  • πŸ” Application Security best practices
  • πŸš€ DevSecOps transformation journeys
  • πŸ› οΈ Security tool integration strategies
  • πŸ“š Security education and awareness programs
  • 🀝 Collaboration on open-source security projects

πŸ›‘οΈ Remember: Security is not a product, but a process

Visitor Count

Popular repositories Loading

  1. htb-arg htb-arg Public

    Notas de Hack The Box

    4

  2. ml-python-utn ml-python-utn Public

    Curso de Machine Learning con Python - UTNBA

    2

  3. react-2021 react-2021 Public

    JavaScript 1

  4. y3rb1t4 y3rb1t4 Public

    1

  5. Algoritmos-y-Estructuras-de-Datos Algoritmos-y-Estructuras-de-Datos Public

    Algoritmos K1051 Jueves

    C++ 1

  6. eko-tf-dast-sast-tools eko-tf-dast-sast-tools Public

    HCL 1