Final-year Computer Science student at Mahidol University International College, working in security advisory and assurance. Most of what I have done so far is hands-on: application penetration testing, incident analysis, and building the tooling around them.
More at pasin.dev.
- BSc Computer Science (on track for First Class Honors), with a minor in Business Administration.
- What interests me is turning a technical finding into a control gap, a business risk, and a recommendation a business can act on.
- I work on both sides of that: offensive testing, and the governance frameworks (ISO/IEC 27001, OWASP Top 10, NIST CSF).
- I also build secure software end to end. Most recently AuditYote, a deployed full-stack GRC platform.
- AuditYote · live. A full-stack governance, risk, and compliance web application. It logs security findings, maps each one to ISO/IEC 27001:2022, OWASP Top 10:2025, and NIST CSF 2.0, and moves it through a role-gated review and sign-off workflow with separation of duties enforced on the server. It scores risk, tracks program-wide posture, keeps an audit trail, and exports CSV and PDF reports. Spring Boot, React, and PostgreSQL, containerized, scanned in CI with Semgrep and Trivy, deployed over HTTPS.
- Security Portfolio. Web application penetration test reports, a ransomware incident analysis, and a mapping of the findings to ISO/IEC 27001:2022, OWASP Top 10:2025, and NIST CSF 2.0 controls. This is the analysis that AuditYote turns into a workflow.
- Security:
Web app pentesting·Malware analysis·Risk and control mapping·Burp Suite·Nmap·Wireshark·Kali Linux - Secure development:
Java / Spring Boot·React / TypeScript·PostgreSQL·Spring Security·Docker·GitHub Actions·Semgrep / Trivy·Python
- Site: pasin.dev
- LinkedIn: linkedin.com/in/pasin-visuttipinate
- TryHackMe: tryhackme.com/p/AvonS10
- Email: pasin.visuttipinate@gmail.com