Product Security Engineer
MercariTokyo, Japan, Hybrid
- Current Product Security Engineer at Mercari.
- Product Security
- Web Application Security
- Security Engineering
Curriculum vitae / 2026
Software Engineering Graduate focused on product security, offensive tooling, and cloud systems.
Tokyo, Japan, Hybrid
Paris, France, Onsite
Tokyo, Japan, Hybrid
Dubai, UAE, Remote
Toulouse, France, Remote
Tunis, Tunisia, Hybrid
Tunis, Tunisia, Hybrid
A modern Burp Suite request minimizer built with Java 21 and the Montoya API.
A Caido plugin for detecting Next.js Server Actions.
A distributed database synchronizer using Golang, Fyne, and RabbitMQ to ensure data consistency between geographically dispersed database parts and a central database, even in case of server failures.
A Python Discord assistant for managing schedules, tasks, and daily workflow noise.
A TypeScript CLI for managing Codex skill profiles.
A Caido community plugin for mapping and visualizing GraphQL endpoints.
A flexible and extensible C2 framework built with Golang and React for managing red team operations during penetration testing missions.
A lab environment for experimenting with LDAP, Kerberos, and DNS, utilizing Docker for ease of use and rapid development.
A project that collects job posting data from various sources like LinkedIn and Twitter, providing real-time and historical insights using Hadoop and Kafka.
A simple website to track job applications, providing a structured approach to managing and improving the application process.
Ein revolutionizes penetration testing with its template-based declarative attack system, Go-powered engine, AI-assisted template generation, and a sleek Svelte frontend.
A website to allow tickets buying and hotel reservations for participants in the National Congress of Cybersecurity
A distributed GUI text editor allowing multiple users to edit the same document simultaneously and remotely. Built using RabbitMQ and Golang.
A collection of smart contracts designed to educate developers about common blockchain vulnerabilities.
An online library management system built using .NET, providing features for managing books, members, and borrowing activities.
A platform for a robotics event, featuring user profiles, conference booking, and a personalized space with Japanese-themed animations.
Solvers for Damn Vulnerable DeFi challenges, utilizing Hardhat.js for testing and exploiting vulnerabilities in decentralized finance applications.
Website to hold course material for workshops on full stack development for students, Held in the summer of 2022.
Get in touch
For product security, backend engineering, CTF collaboration, or speaking opportunities.
Software Engineering Graduate | Product Security Engineer
Product Security Engineer and software engineering graduate with experience in application security, Rust and Go backend development, offensive security tooling, CTF organization, and bug bounty research.
Mercari
Dec 2025 to Present | Tokyo, Japan | Hybrid
Stockly
Feb 2025 to Aug 2025 | Paris, France | Onsite
Mercari
Jun 2024 to Aug 2024 | Tokyo, Japan | Hybrid
CTF.ae
Jan 2024 to Present | Dubai, UAE | Remote
PCP Consulting
May 2023 to Dec 2023 | Toulouse, France | Remote
K-Noon
Feb 2023 to Jul 2024 | Tunis, Tunisia | Hybrid
Languages: Rust, Go, Python, TypeScript, C, C#, Bash Scripting
Security: Product Security, OWASP TOP 10, Burp Suite, Secure Code Audit
Backend and cloud: REST, GraphQL, SQL Databases, GCP, AWS, Docker, Kubernetes, CI/CD
A modern Burp Suite request minimizer built with Java 21 and the Montoya API.
A Caido plugin for detecting Next.js Server Actions.
A distributed database synchronizer using Golang, Fyne, and RabbitMQ to ensure data consistency between geographically dispersed database parts and a central database, even in case of server failures.
A Python Discord assistant for managing schedules, tasks, and daily workflow noise.
MSc in Software Engineering, National Institute of Applied Sciences and Technology2021 to 2025