Kenzie TanderaFull-Stack Developer · Penetration Tester

Osaka, Japan12:24 JST

Full-Stack Developer Penetration Tester

Kenzie Tandera

I build systems end to end — then I try to break them. Full-stack engineering with a security researcher’s instinct for where things give way.

Osaka, Japan HAL Osaka Vocational College

About

02 — About

I’m a student at HAL Osaka, building production software by day and taking it apart by night.

Most of what I know came from shipping things that had to actually work — APIs that stay up, interfaces people can move through without thinking, and tooling that removes the boring parts of a workflow. I write across the stack because the interesting problems rarely respect the boundary between front and back.

The security side started as curiosity and turned into discipline. Working through authorized assessments taught me to read a system the way an attacker does: assume nothing, verify everything, and pay attention to the seams where two components agree to trust each other.

I’m mentored by a former Netflix Senior Cloud Engineer, which reset my sense of what “done” means. Reliability at scale, observability, blast-radius thinking — the habits that separate a project from a product.

Based in
Osaka, Japan
Studying
HAL Osaka Vocational College
Mentored by
Ex-Netflix Senior Cloud Engineer
Focus
Full-stack systems & offensive security

03 — Experience

What I do

  1. Penetration Tester

    Authorized engagements & private programs

    Black- and grey-box assessments of web applications under written authorization. Reconnaissance, manual verification, impact analysis, and reporting written for the people who have to fix it — reproduction steps, severity rationale, and remediation guidance.

    • Web App Testing
    • Recon
    • CVSS
    • Reporting
    • Responsible Disclosure
    Present
  2. Full-Stack Developer

    Product work & freelance builds

    End-to-end delivery: schema design, REST APIs, authentication, and the interface on top. Comfortable owning a feature from an empty migration file through to the animation that makes it feel finished.

    • TypeScript
    • NestJS
    • Angular
    • PostgreSQL
    • Redis
    Present
  3. Software Engineering Mentee

    Mentored by a former Netflix Senior Cloud Engineer

    Regular review of architecture and code against production standards — failure modes, observability, deployment strategy, and the cost of every abstraction. The fastest source of growth I have.

    • System Design
    • Cloud Architecture
    • Code Review
    • Reliability
    Ongoing
  4. Game Reverse Engineer

    Independent research

    Binary and protocol analysis for the sake of understanding how the machine really behaves. Memory layout, packet structure, and client logic — the discipline that makes every other kind of debugging feel easy.

    • Reverse Engineering
    • Binary Analysis
    • Protocol Analysis
    • Debugging
    Personal

04 — Security Research

Authorized assessments

Authorized

Reported & acknowledged

Polygon Technology

Web application

CVSS 7.5Severity score
HighSeverity

An authorized assessment conducted through a private bug bounty program. A single high-severity issue was identified, validated, and disclosed to the vendor through their coordinated channel. Details remain confidential under the program’s disclosure terms.

ChannelHackerOne — private program

Authorized

Reported to owner

harfit.co.id

WordPress platform

6 findingsReported issues
MultipleSeverity

A permissioned review of a production WordPress deployment covering configuration, exposed surface, and platform hygiene. Six issues were documented with severity ratings and remediation guidance, then handed to the site owner privately. No technical specifics are published.

ChannelDirect engagement — written authorization

All work described here was performed with explicit written authorization or under the terms of a public bug bounty program. No vulnerability details, payloads, or proof-of-concept material are published.

05 — Selected Work

Things I’ve built

  • AI CV Scorer2025

    Scores a résumé against a job description and explains the gap.

  • Expense Tracker2025

    Personal finance tracking that stays out of your way.

  • CLI Tool2025

    Removes the ritual from the commit-and-push loop.

  • Editorial Web2024

    A discography and archive built as a love letter.

  • Security Tooling2026

    Reconnaissance and assessment tooling. Private repository.

    Active development

06 — Skills

The constellation

Five clusters, wired together out there in the dark. Trace one to light it up.

    • Go
    • Nuclei
    • Burp Suite
    • OWASP ZAP
    • Nmap
    • HackerOne
    • TypeScript
    • JavaScript
    • Go
    • Kotlin
    • Bash
    • PowerShell
    • Angular
    • React
    • Three.js
    • GSAP
    • HTML
    • CSS
    • Node.js
    • NestJS
    • Fastify
    • PostgreSQL
    • Redis
    • TypeORM
    • JWT
    • Vercel
    • DigitalOcean
    • Google Cloud
    • Git

07 — Contact

Let’s buildsomething

Open to internships, freelance work, and security research collaboration. If you have something worth breaking or building, I’d like to hear about it.

© 2026 Kenzie Tandera — Osaka, Japan

Built with Angular, Three.js and GSAP. Lit by a cold moon.