Web & API security
Auth/authz review, OWASP-focused testing, and developer-ready findings.
I work across cloud security (AWS, GCP), web and API security, penetration testing, Kubernetes, and DevSecOps. I secure infrastructure, validate real attack paths, and deliver remediation plans teams can implement—so you ship safely and stay audit-ready.
Consulting: Hien Nguyen Cybersecurity — services, case studies, reports, and blog.
Cloud (AWS/GCP) · Web & API security · Penetration testing · Kubernetes · DevSecOps · Compliance (SOC 2, ISO 27001, PCI)
Remote, EU timezone · Response within 24–48 hours · Fixed quote after scope
I'm a security engineer with 7+ years in offensive security, cloud security (AWS/GCP), and DevSecOps. I help SaaS and fintech teams reduce risk and ship safely—through audits, penetration testing, and security architecture. For more on background and approach, see About on the consulting site.
My work spans application security, cloud security, and delivery pipelines — focused on practical outcomes for product and engineering teams.
Auth/authz review, OWASP-focused testing, and developer-ready findings.
IAM design, exposure review, logging/monitoring readiness, and scalable guardrails.
Cluster and workload hardening, isolation, secrets handling, and deployment risks.
Secure pipelines, dependency trust, secrets management, and release controls.
Threat modeling, multi-tenant patterns, and compliance-aware control choices.
Identified and validated exploitation paths with clear impact and practical fixes.
Found role boundary and access-control issues and helped teams close them with re-testable remediation.
Reduced exposure from public access and over-permissive IAM; improved logging and alerting posture.
Helped teams move toward SOC 2 / ISO 27001 readiness with engineering-friendly evidence and control choices.
I focus on security that holds up in real engineering environments: fast shipping, multiple environments, legacy constraints, and limited time.
Selected writeups and deliverable examples live on Hien Nguyen Cybersecurity.
Threat research series and write-ups for recruiters and clients. One place to see depth in AppSec, cloud security, and offensive security.
Hub for threat research series, technical write-ups, blog, and case studies. Start here to scan the full portfolio.
View Research IndexCurated multi-post series: SaaS security, cloud IAM, API abuse. Structured for quick scanning and deep reading.
View seriesTechnical write-ups with methodology, findings, and remediation. Tied to blog and case studies.
View write-upsHiring for Security Engineer, Security Researcher, AppSec, Cloud Security, or DevSecOps? I have 7+ years across offensive security, cloud (AWS/GCP), and application security. Evidence: Research Index, case studies, and blog. Remote, EU timezone. Happy to discuss fit and share a CV.
Contact meScoped security testing, cloud audits, or architecture review. See services, case studies, and report deliverables. Fixed quote after scope; response within 24–48 hours.
View services Book consultationAvailable: Remote, Europe
Response time: Within 24–48 hours
Reach out directly for consulting inquiries, quick advice sessions, or to discuss scope.
Email me Full intake form →Professional micro-consulting for focused outcomes. Calm, practical guidance without the overhead of a full engagement.
€20 / hour
Best for: students and early professionals
€60 / hour
Best for: individuals and small teams
Remote, EU timezone • Response within 24–48 hours • Fixed quote for larger engagements