About
/overviewI work at the intersection of security engineering and software delivery, with a bias toward building practical controls instead of adding friction.
I’m Luis Rodriguez Castro, an Application Security Engineer focused on secure design, threat modeling, code review, cloud security, and building security workflows that support engineering velocity.
$ whoami Luis Rodriguez Castro $ focus --today - application security engineering - threat modeling (STRIDE) - cloud security in AWS - security tooling & automation - secure code review $ philosophy security should scale
I work at the intersection of security engineering and software delivery, with a bias toward building practical controls instead of adding friction.
A practical mix of application security, cloud security, and software engineering.
Systems designed to make security easier to adopt and harder to ignore.
Built automation to process security findings, reduce manual triage, and route remediation work more efficiently.
Designed scalable scanning workflows using AWS services and automated domain discovery to keep targets fresh.
Worked on a CLI tool using Go to help security teams manage vulnerabilities, track remediation progress, and generate reports for stakeholders.
Performed STRIDE-based analysis for modern application and tokenization architectures, mapping threats to actionable mitigations.
A quick view of the environments where I’ve applied application security, cloud security, and engineering-focused practices.
Performed application security efforts with an emphasis on practical controls, architecture review, secure code review, vulnerability management, tool development and secure engineering collaboration.
Built and maintained security tooling, integrated security into CI/CD, performed secure code reviews, validated findings, and supported scalable security processes across engineering teams.
Expanding into the Cloud with AWS and IAC-based infrastructure, deeper secure design work with threat modeling, exploring low-level security concepts to better understand how to secure complex systems and AI security topics as they evolve.