Kenzie Tandera

Full-Stack Developer and Penetration Tester — Osaka, Japan.

I build systems end to end — then I try to break them. Full-stack engineering with a security researcher’s instinct for where things give way.

About

I’m a student at HAL Osaka, building production software by day and taking it apart by night.

Most of what I know came from shipping things that had to actually work — APIs that stay up, interfaces people can move through without thinking, and tooling that removes the boring parts of a workflow. I write across the stack because the interesting problems rarely respect the boundary between front and back.

The security side started as curiosity and turned into discipline. Working through authorized assessments taught me to read a system the way an attacker does: assume nothing, verify everything, and pay attention to the seams where two components agree to trust each other.

I’m mentored by a former Netflix Senior Cloud Engineer, which reset my sense of what “done” means. Reliability at scale, observability, blast-radius thinking — the habits that separate a project from a product.

Based in
Osaka, Japan
Studying
HAL Osaka Vocational College
Mentored by
Ex-Netflix Senior Cloud Engineer
Focus
Full-stack systems & offensive security

Experience

Penetration Tester

Authorized engagements & private programs — Present

Black- and grey-box assessments of web applications under written authorization. Reconnaissance, manual verification, impact analysis, and reporting written for the people who have to fix it — reproduction steps, severity rationale, and remediation guidance.

Web App Testing, Recon, CVSS, Reporting, Responsible Disclosure

Full-Stack Developer

Product work & freelance builds — Present

End-to-end delivery: schema design, REST APIs, authentication, and the interface on top. Comfortable owning a feature from an empty migration file through to the animation that makes it feel finished.

TypeScript, NestJS, Angular, PostgreSQL, Redis

Software Engineering Mentee

Mentored by a former Netflix Senior Cloud Engineer — Ongoing

Regular review of architecture and code against production standards — failure modes, observability, deployment strategy, and the cost of every abstraction. The fastest source of growth I have.

System Design, Cloud Architecture, Code Review, Reliability

Game Reverse Engineer

Independent research — Personal

Binary and protocol analysis for the sake of understanding how the machine really behaves. Memory layout, packet structure, and client logic — the discipline that makes every other kind of debugging feel easy.

Reverse Engineering, Binary Analysis, Protocol Analysis, Debugging

Security research

Polygon Technology

Web application — High (CVSS 7.5)

HackerOne — private program — Reported & acknowledged

An authorized assessment conducted through a private bug bounty program. A single high-severity issue was identified, validated, and disclosed to the vendor through their coordinated channel. Details remain confidential under the program’s disclosure terms.

harfit.co.id

WordPress platform — Multiple (6 findings)

Direct engagement — written authorization — Reported to owner

A permissioned review of a production WordPress deployment covering configuration, exposed surface, and platform hygiene. Six issues were documented with severity ratings and remediation guidance, then handed to the site owner privately. No technical specifics are published.

All work described here was performed with explicit written authorization or under the terms of a public bug bounty program. No vulnerability details, payloads, or proof-of-concept material are published.

Selected work

Matchingg

AI CV Scorer — 2025

Matchingg reads a CV and a job posting, then returns a match score with the reasoning attached — which requirements are covered, which are missing, and what phrasing is costing the candidate points.

The hard part was making the output trustworthy rather than merely confident: structured extraction first, scoring second, so every number traces back to something actually present in the document.

Built with TypeScript, NestJS, PostgreSQL, LLM APIs, Angular.

Visit Matchingg

Expenss

Expense Tracker — 2025

A tracker built around the reality that people abandon finance apps within a week. Entry is fast, categories learn from what you already logged, and the summary answers the only question that matters: where did it go.

Behind it sits a normalized schema with proper currency handling and a reporting layer that aggregates on the database rather than in the client.

Built with TypeScript, Fastify, PostgreSQL, TypeORM, Redis.

Visit Expenss

Gitauto

CLI Tool — 2025

A command-line tool for the repetitive half of version control — staging, conventional commit messages, branch hygiene, and push, collapsed into a single intentional command.

Written to be predictable above all: it never rewrites history you did not ask it to rewrite, and every destructive path requires confirmation.

Built with Go, Bash, Git Plumbing.

Gitauto repository

RADWIMPS Fansite

Editorial Web — 2024

A fan-built archive for RADWIMPS — releases, timelines, and lyric context, laid out with the kind of typographic care the music deserves.

Entirely front-end craft: responsive editorial layout, image performance discipline, and motion that supports the reading rather than interrupting it.

Built with Angular, TypeScript, CSS, GSAP.

Visit RADWIMPS Fansite

Pentrate

Security Tooling — 2026

Pentrate is an internal toolkit for authorized security assessments — orchestrating reconnaissance, normalizing scanner output, and turning scattered results into a single reviewable report.

It exists because the slowest part of an engagement is rarely the testing; it is the collation. The project is under active development and the repository stays private, as does everything it has ever produced.

Built with Go, Nuclei, Nmap, PostgreSQL, CLI.

Private repository — no public source or demo.

Skills

Security

Offensive testing & research

Go, Nuclei, Burp Suite, OWASP ZAP, Nmap, HackerOne

Languages

Daily drivers

TypeScript, JavaScript, Go, Kotlin, Bash, PowerShell

Frontend

Interface & motion

Angular, React, Three.js, GSAP, HTML, CSS

Backend

Services & data

Node.js, NestJS, Fastify, PostgreSQL, Redis, TypeORM, JWT

Platform

Ship & operate

Vercel, DigitalOcean, Google Cloud, Git

Contact

tandera.kenzie@gmail.com

Kenzie TanderaFull-Stack Developer · Penetration Tester

Osaka, Japan15:35 JST