~/about
Hi, I'm Wahyudi.
Software engineer by trade, attacker by curiosity. I specialize in building reliable, testable software and in finding where it breaks.
Software Engineer · SDET · Application Security · Security Researcher
The short version
I'm a software engineer who spent years writing production code and test automation, then turned that understanding toward breaking the same kind of systems defensively. As an SDET I build automated test infrastructure that blocks regressions early; as anApplication Security engineer I review, harden and pentest them; as a Security Researcher I hunt real bugs across bug bounty programs and walk every finding through responsible disclosure.
The methodology section is a living document — every procedure started as a note taken while testing a production target. This is the same playbook I follow on scoped engagements and bounty programs, and it doubles as my research log.
What I optimize for
I break things to understand failure modes, then feed the lessons straight back into design, code review and test suites.
As an SDET I turn fragile manual checks into deterministic automation — the same discipline applies to recon and scanning.
Every finding is validated, scoped and reported before it can become someone else's CVE. Disclosure is a feature, not an afterthought.
Experience
Security Researcher
ongoingBug bounty programs · HackerOne
- ▸Multi-program coverage: web, API, mobile.
- ▸Reproducible, business-impact-focused reports.
Application Security
ongoingFreelance
- ▸Threat modeling and secure code review.
- ▸Patching, hardening and CVE triage.
SDET / Quality Engineer
ongoingFreelance
- ▸API & E2E test automation at scale.
- ▸Shift-left testing inside CI/CD.
Software Engineer
ongoingFreelance
- ▸Full-stack web and mobile apps.
- ▸Security as a default rather than a phase.