Building dependable software and finding where systems fail.

I develop JVM and backend systems, then bring the same attention to failure modes into private vulnerability research: remote code execution, memory corruption, and privilege escalation.

Selected public work

Small tools built for actual use. Private research is intentionally absent while vendor disclosure restrictions apply.

School schedule viewer

Fast class and teacher timetables in Bosnian, designed around mobile use.

Open schedule

Regex tester

Live JavaScript matches, capture groups, highlighting, and a pattern breakdown.

Open tester

Loan calculator

Fixed and diminishing repayment comparisons with amortisation details.

Open calculator

Current practice

Engineering and research are separate engagements, but they share the same method: reduce the problem, verify the evidence, and document the result.

Private vulnerability research

Audit operating systems, cloud services, and enterprise platforms through private programmes and coordinated disclosure.

Backend engineering

Build services, APIs, and data systems with the JVM ecosystem, databases, and event-driven infrastructure.

Performance work

Investigate latency, concurrency, allocation, and resource use in systems where predictable behaviour matters.

Technical reporting

Produce minimal reproductions, impact analysis, and remediation notes that another engineer can verify.

Experience

A concise record of the work I do and the environments I work in.

Private practiceCurrent

Vulnerability researcher and security auditor

  • Research remote code execution, memory corruption, and privilege-escalation vulnerabilities.
  • Work within private bug-bounty programmes and coordinated-disclosure embargoes.
  • Prepare reproducible findings for vendor security teams and CVE coordination.

Focus: vulnerability research, reverse engineering, exploitability assessment, CVD

Independent2021–present

Software engineer, contract and freelance

  • Built high-performance Minecraft server extensions under strict latency requirements.
  • Delivered web applications from data modelling and API design through deployed interfaces.
  • Designed event-driven services with payments, authentication, and notification integrations.
  • Prototyped systems components in Zig for throughput-sensitive workloads.

Tools: Java, Kotlin, Spring Boot, PostgreSQL, MongoDB, Redis, React, Zig, Docker

Open source2024–present

JVM ecosystem contributor

  • Contribute to server libraries, performance tooling, and Spring Boot starter projects.
  • Maintain small Kotlin libraries and publish work through GitHub.

Tools: Kotlin, Java, Gradle, GitHub Actions

Technical skills

Tools I use in production and research work, grouped by purpose rather than proficiency labels.

SecurityVulnerability auditing, reverse engineering, exploitability assessment, coordinated disclosure, technical reporting
LanguagesJava, Kotlin, SQL, JavaScript, TypeScript, Zig, Bash
BackendSpring Boot, Spring MVC, WebFlux, Spring Security, Hibernate, REST and GraphQL APIs
DataPostgreSQL, MongoDB, Redis, RabbitMQ, Kafka
DeliveryDocker, Kubernetes, Gradle, Maven, GitHub Actions, SonarQube
VerificationJUnit, Mockito, Testcontainers, JVM profiling, Prometheus, Grafana, structured telemetry

Contact

Available for private security research, backend engineering, and focused contract work. Email is the most direct way to reach me.