Hola! I am Roberto, a full stack developer with five years of professional experience and a deep focus on application security. I build production software and actively research vulnerabilities. The goal is straightforward: write code that is harder to break and catch what others miss before it ships.
I care about clean architecture, long-term maintainability, and code that does not become a liability six months later. I have worked in small teams with no dedicated QA or DevOps function, which meant covering those gaps hands-on: testing, CI/CD, deployment, and infrastructure. One thing I built proactively was an SBOM pipeline to audit internal libraries and flag vulnerable dependencies before they reached production. Nobody asked for it. It was just the obvious thing to do once you start thinking about attack surface. I have also set up application middleware and attribute-level audit tables to keep a traceable record of sensitive operations, the kind of accountability layer that matters the moment you need to answer who changed what and when.
I hunt vulnerabilities on Bugcrowd and approach it the same way I approach development: methodically, with reproducible steps and clear documentation. My academic background is in secure application development and I am currently working toward my Network+ to sharpen my understanding of the network layer. Better networking fundamentals make me a stronger developer, a more useful QA reviewer, and more effective in a production incident.
If you are building something that handles real users, real data, or real money and you want someone who thinks about what can go wrong before it does, I am happy to connect.
Check out my research journal at archive.robertovallado.dev, my resume cv.robertovallado.dev or find me on LinkedIn