• File

Personal information hidden

This job seeker decided to hide his personal information and contact info, but you can send a message to him or suggest a job to him.

This job seeker has chosen to hide his personal information and contact info. You can contact him using this page: https://www.work.ua/resumes/20011228/

Application Security Engineer

City of residence:
Kyiv
Ready to work:
Kyiv, Remote

Contact information

This job seeker has hidden his personal information, but you can send him a message or suggest a job to him if you open his contact info.

Name, contacts and photo are only available to registered employers. To access the candidates' personal information, log in as an employer or sign up.

Uploaded file

Quick view version

This resume is posted as a file. The quick view option may be worse than the original resume.

Hanna Nyzhnia
Application Security Engineer · OWASP · Secure SDLC

[open contact info](look above in the "contact info" section) | [open contact info](look above in the "contact info" section) | [open contact info](look above in the "contact info" section) | github.com/grepxz | nyzhnia.com | Barcelona, Spain

PROFESSIONAL SUMMARY

Application Security engineer who came in through offensive security and governance and then learned to build. M.S. in Cybersecurity, web
and mobile penetration testing through EPAM's bootcamp (Metasploit, Nmap, OWASP-aligned reporting), and a year at KPMG assessing
bank applications against ISO 27001 and NIST. I implement security in the pipeline: supply-chain scanning with Trivy and tfsec, policy-as-
code with Kyverno, and keyless OIDC CI/CD on AWS EKS, all provisioned with Terraform. I work in Python, Bash, and Node.js / JavaScript
across web, mobile, and AWS microservices.

CORE COMPETENCIES

Application Security (AppSec) OWASP Top 10 Manual Penetration Testing Threat Modeling AWS Cloud Security (IaaS)

Node.js / TypeScript Python & Bash Security Frameworks (ISO 27001 / NIST)

WORK EXPERIENCE

Archilabs Sep 2024 - Feb 2025
Full Stack Developer · Houston, TX (Remote)

Engineered a web application converting AutoCAD drawings into real-time interactive 3D renders, applying secure coding practices across the
Node.js stack.
Optimized backend services for browser-based rendering, sustaining 200+ concurrent users with reduced latency.

Mission Zero May 2023 - Dec 2023
Full Stack Developer · Houston, TX

Designed scalable backend (Node.js) supporting 5,000 concurrent users and integrated REST APIs into a React Native mobile frontend across
15,000+ downloads.
Hardened data synchronization between mobile client and backend services, improving efficiency by 35%.

KPMG Dec 2021 - Dec 2022
Cybersecurity Consultant · Kyiv, Ukraine
Assessed bank applications and systems against ISO 27001 / 27002, NIST, and VAIT across a 5-client portfolio; identified and reported
vulnerabilities; lifted compliance ~40%.
Provided technical guidance to developers, translating audit findings into remediation that engineering teams adopted into delivery and
change-management processes.

PROJECTS

Web Penetration Testing Bootcamp - EPAM Manual Pentest & OWASP

Intensive hands-on web and mobile penetration testing with Metasploit and Nmap: vulnerability identification, threat modeling, and OWASP-
aligned remediation reporting across web applications and mobile clients.
Tech: OWASP Top 10, Metasploit, Nmap, threat modeling, manual vulnerability assessment

Project-Ramus - Application Security & AWS IaaS Hardening AppSec + Cloud github.com/grepxz/Project-Ramus

Built a security-first delivery platform on AWS EKS (Kubernetes v1.30): supply-chain scanning with Trivy and tfsec, policy-as-code with
Kyverno, keyless GitHub Actions CI/CD via AWS OIDC (no long-lived credentials), and secrets managed by the External Secrets Operator backed
by AWS Secrets Manager. Terraform-provisioned end to end.
Tech: AWS (EKS, IAM, Secrets Manager, OIDC), Trivy, tfsec, Kyverno, Terraform, ArgoCD, GitHub Actions

Project-Gemma - Automated CI/CD on AWS CI/CD github.com/grepxz/Project-Gemma

Hands-free Jenkins + Docker pipeline that deploys a Flask + MySQL application to AWS EC2 on every push.
Tech: Jenkins, Docker, Docker Compose, AWS EC2, MySQL, Linux

EDUCATION

M.S., Cybersecurity - Kyiv National University of Construction and Architecture Jan 2023

SKILLS

Application Security: OWASP Top 10, manual penetration testing (Metasploit, Nmap), threat modeling, vulnerability identification, secure code
review, secure SDLC

Cloud & IaaS Security: AWS (EC2, EKS, IAM, Secrets Manager, OIDC, CloudTrail concepts), Kubernetes security, Terraform, policy-as-code
(Kyverno), supply-chain scanning (Trivy, tfsec)
Security Frameworks: ISO 27001 / 27002, NIST, VAIT, GDPR awareness, cryptography, authentication / authorization, incident response

Programming: Python, Bash, JavaScript / Node.js, TypeScript (working knowledge), SQL (MySQL)

Web & Mobile: REST APIs, React / React Native, microservices, TLS / HTTPS / DNS

AI Tooling: Claude, Cursor, Copilot for code review, security policy drafting, and documentation
Languages: Ukrainian (native), English (fluent), Russian (fluent), Spanish (A1)

More resumes of this candidate

Similar candidates

All similar candidates

Candidates at categories