Skip to content
View AvonS10's full-sized avatar

Highlights

  • Pro

Block or report AvonS10

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
AvonS10/README.md

Pasin Visuttipinate (Ryo)

Final-year Computer Science student at Mahidol University International College, working in security advisory and assurance. Most of what I have done so far is hands-on: application penetration testing, incident analysis, and building the tooling around them.

More at pasin.dev.

About

  • BSc Computer Science (on track for First Class Honors), with a minor in Business Administration.
  • What interests me is turning a technical finding into a control gap, a business risk, and a recommendation a business can act on.
  • I work on both sides of that: offensive testing, and the governance frameworks (ISO/IEC 27001, OWASP Top 10, NIST CSF).
  • I also build secure software end to end. Most recently AuditYote, a deployed full-stack GRC platform.

Featured

  • AuditYote · live. A full-stack governance, risk, and compliance web application. It logs security findings, maps each one to ISO/IEC 27001:2022, OWASP Top 10:2025, and NIST CSF 2.0, and moves it through a role-gated review and sign-off workflow with separation of duties enforced on the server. It scores risk, tracks program-wide posture, keeps an audit trail, and exports CSV and PDF reports. Spring Boot, React, and PostgreSQL, containerized, scanned in CI with Semgrep and Trivy, deployed over HTTPS.
  • Security Portfolio. Web application penetration test reports, a ransomware incident analysis, and a mapping of the findings to ISO/IEC 27001:2022, OWASP Top 10:2025, and NIST CSF 2.0 controls. This is the analysis that AuditYote turns into a workflow.

Skills

  • Security: Web app pentesting · Malware analysis · Risk and control mapping · Burp Suite · Nmap · Wireshark · Kali Linux
  • Secure development: Java / Spring Boot · React / TypeScript · PostgreSQL · Spring Security · Docker · GitHub Actions · Semgrep / Trivy · Python

Connect

Pinned Loading

  1. AvonS10 AvonS10 Public

    My GitHub profile README.

  2. security-portfolio security-portfolio Public

    Hands-on security work from authorized labs: web-app penetration test reports, a ransomware incident analysis, and the findings mapped to ISO 27001, OWASP Top 10, and NIST CSF controls.

    1

  3. audityote audityote Public

    AuditYote - full-stack GRC web app: map security findings to controls across ISO 27001 / OWASP Top 10 / NIST CSF, with a role-gated review & sign-off workflow, risk scoring/posture, and CSV/PDF com…

    Java 1

  4. Ponger Ponger Public

    Forked from K-Planky/Ponger

    Python 1