Mugeha Jackline
About me
I break applications to understand how to secure them, and build security in before attackers get a chance. I focus on application security, with a strong interest in web and API security, as well as secure system design. My work sits at the intersection of how applications are built and how they can be broken. I’ve done hands-on testing of web and API-based systems, focusing on authentication flaws, broken access control (including IDOR), misconfigurations, and common vulnerabilities mapped to the OWASP Top 10(both Mobile and Web) and API Security Top 10. I’m comfortable using tools like Burp Suite, Postman, MobSF, Nmap, Metasploit, and curl to identify, validate, and document security issues. Beyond offensive testing, I care about secure design and risk awareness. I’ve worked with secure API authentication mechanisms and understand the importance of governance and reporting in regulated environments. I can translate technical findings into clear, structured security reports that decision-makers can act on.
I’m continuously building my skills through hands-on labs, real-world scenarios, and deep dives into modern attack surfaces. I document what I learn and stay focused on practical, real-world security, not just theory.
I’m actively exploring opportunities in Application Security, Product Security, and Security Engineering, where I can grow under strong mentorship while contributing a security-first mindset.