~/about

Hi, I'm Wahyudi.

Software engineer by trade, attacker by curiosity. I specialize in building reliable, testable software and in finding where it breaks.

Software Engineer · SDET · Application Security · Security Researcher

The short version

I'm a software engineer who spent years writing production code and test automation, then turned that understanding toward breaking the same kind of systems defensively. As an SDET I build automated test infrastructure that blocks regressions early; as anApplication Security engineer I review, harden and pentest them; as a Security Researcher I hunt real bugs across bug bounty programs and walk every finding through responsible disclosure.

The methodology section is a living document — every procedure started as a note taken while testing a production target. This is the same playbook I follow on scoped engagements and bounty programs, and it doubles as my research log.

What I optimize for

↳ Attack with intent

I break things to understand failure modes, then feed the lessons straight back into design, code review and test suites.

↳ Automate the boring parts

As an SDET I turn fragile manual checks into deterministic automation — the same discipline applies to recon and scanning.

↳ Hunt ethically

Every finding is validated, scoped and reported before it can become someone else's CVE. Disclosure is a feature, not an afterthought.

Experience

Security Researcher

ongoing

Bug bounty programs · HackerOne

  • ▸Multi-program coverage: web, API, mobile.
  • ▸Reproducible, business-impact-focused reports.

Application Security

ongoing

Freelance

  • ▸Threat modeling and secure code review.
  • ▸Patching, hardening and CVE triage.

SDET / Quality Engineer

ongoing

Freelance

  • ▸API & E2E test automation at scale.
  • ▸Shift-left testing inside CI/CD.

Software Engineer

ongoing

Freelance

  • ▸Full-stack web and mobile apps.
  • ▸Security as a default rather than a phase.