Back to portfolio

Six focused CVs · one verified career history

Viewing

Security-Minded Software Engineer

Download PDF

05 / DEFENSIVE

Tornike Kalandadze

Security-Minded Software Engineer

Application security · Defensive tooling · Threat modeling

tornikekalandadze.work@gmail.com+995 599 258 808Tbilisi, Georgia · GMT+4github.com/stariiklinkedin.com/in/tornike-kalandadze-997701365
Top 4%TryHackMe
91rooms completed
98NetLens core tests

Profile

Security-minded software engineer with hands-on application-security training and a portfolio of deliberately defensive systems. I build around distrust: bounded parsing, sandboxed execution, default-deny authorization, secure evidence handling, audit logs, explainable findings, and documented limitations. TryHackMe: top 4%, 91 rooms, 15 badges, four completed learning paths.

Experience

Independent Security Engineer

Defensive engineering & authorized labs

  • Build defensive systems around hostile-input handling, sandboxing, authentication, authorization, auditability, and explainable findings.
  • Completed 91 TryHackMe rooms, earned 15 badges, reached the top 4%, and completed four security learning paths in 2023.
  • Keep offensive practice inside authorized labs; public projects are deliberately defensive and document their limitations.

Winner · Solo Builder

ShieldMesh · VibeCoding From 0

  • Built an offline-first mobile threat-intelligence system end to end: Android app, local threat detection, device-to-device alert relay, Solana devnet program, and public dashboard.
  • Shipped a downloadable APK and working demo as the hackathon’s championship winner.
Tornike KalandadzeSecurity-Minded Software Engineer05 / DEFENSIVE

Selected engineering work

NetLens

Defensive prototype

github.com/stariik/NetLens

Passive, offline PCAP-forensics backend that validates hostile captures and normalizes Zeek/Suricata evidence.

  • Docker analysis jail: no network, dropped capabilities, read-only root, non-root user, no-new-privileges, and CPU/memory/PID/time ceilings.
  • 98 core tests; ten explainable heuristics present rationale, calculations, benign explanations, and validation steps.

Python · FastAPI · Zeek · Suricata · Docker · PostgreSQL

SentinelForge

Defensive prototype

github.com/stariik/SentinelForge

Versioned Sigma-rule workspace with safe import, explainable scoring, ATT&CK mapping, RBAC, and audit history.

  • Bounds YAML and ZIP inputs against traversal, symlinks, nesting, expanded size, entry count, and compression-ratio abuse.
  • Immutable versions and diffs make restoration non-destructive; production refuses to start with the example secret.

FastAPI · pySigma · SQLAlchemy · MITRE ATT&CK · JWT

PentestFlow

Authorized-assessment prototype

github.com/stariik/pentestflow

Engagement workspace that converts imported scanner output into triage, evidence, attack paths, findings, and redacted reports.

  • Parses Nmap, Nuclei, Burp, ZAP, and Nikto output strictly as data; it contains no scanner, payload delivery, or command execution.
  • Central engagement authorization, audit logging, sanitized Markdown, computed CVSS v3.1, and automatic secret redaction.

Next.js 15 · PostgreSQL · Prisma · Auth.js · Playwright

ShieldMesh

Solo hackathon winner

github.com/stariik/shieldmesh

Offline-first threat-intelligence system spanning Android, local detection, device-to-device relay, and Solana verification.

  • Built solo for VibeCoding From 0 and won the championship plus an $800 prize.
  • Delivered a downloadable APK, Room-backed offline state, devnet Anchor program, and public Next.js dashboard.

Kotlin · Jetpack Compose · Room · Rust · Anchor · Solana

Worldwide remote · employment, contract, or freelance

Portfolio evidence and source code available through the links above.

The web treatment changes by discipline; every downloaded PDF preserves straightforward headings, selectable text, and ATS-readable content.