I’m Pedro Mauricio Morales , an Application Security Engineer and Python developer with 8+ years of hands-on experience helping teams build and defend modern web applications. I specialize in secure code review, OWASP Top 10 mitigations, input validation, broken access control prevention, and API security, often strengthening both Python back ends and complex JavaScript/TypeScript front ends. I’m also comfortable operating in high-stakes environments, bringing an incident-response mindset and disciplined OpSec practices into my day-to-day work. Across roles spanning full-stack security, code auditing, and cloud-focused architecture reviews (AWS), I collaborate with engineering teams to triage security issues, improve remediation lifecycles, and deliver safer, more reliable systems.

Pedro Mauricio Morales

I’m Pedro Mauricio Morales , an Application Security Engineer and Python developer with 8+ years of hands-on experience helping teams build and defend modern web applications. I specialize in secure code review, OWASP Top 10 mitigations, input validation, broken access control prevention, and API security, often strengthening both Python back ends and complex JavaScript/TypeScript front ends. I’m also comfortable operating in high-stakes environments, bringing an incident-response mindset and disciplined OpSec practices into my day-to-day work. Across roles spanning full-stack security, code auditing, and cloud-focused architecture reviews (AWS), I collaborate with engineering teams to triage security issues, improve remediation lifecycles, and deliver safer, more reliable systems.

Available to hire

I’m Pedro Mauricio Morales , an Application Security Engineer and Python developer with 8+ years of hands-on experience helping teams build and defend modern web applications. I specialize in secure code review, OWASP Top 10 mitigations, input validation, broken access control prevention, and API security, often strengthening both Python back ends and complex JavaScript/TypeScript front ends.

I’m also comfortable operating in high-stakes environments, bringing an incident-response mindset and disciplined OpSec practices into my day-to-day work. Across roles spanning full-stack security, code auditing, and cloud-focused architecture reviews (AWS), I collaborate with engineering teams to triage security issues, improve remediation lifecycles, and deliver safer, more reliable systems.

See more

Experience Level

Expert
Expert
Expert
Intermediate

Language

English
Advanced
Spanish; Castilian
Advanced

Work Experience

Software Engineer / AppSec Consultant at Leoport Industries
October 1, 2024 - Present
Conducted regular secure code reviews of Python back ends, addressing OWASP Top 10 risks such as injection, broken access control, and SSRF. Reviewed proposed cloud and pipeline solutions against strict customer security requirements, emphasizing zero-trust style AWS deployment configurations. Built scalable, maintainable, and type-safe Python/TypeScript modules with secure input validation and parameterization to protect data endpoints. Collaborated cross-functionally with engineering teams to triage security defects and coordinate status updates, accelerating remediation for critical business software.
Incident Response & Compliance Lead at Sacramento Conservation Corps
August 1, 2022 - December 1, 2023
Led operational safety teams under strict state compliance guidelines, enforcing incident command protocols during high-stakes environmental mitigation tasks. Conducted localized risk assessments and asset protection planning, executing physical and perimeter containment strategies to safeguard public utility infrastructure. Orchestrated logistics including inventory tracking, equipment logging, and team deployments to maintain data integrity and workflow efficiency across remote operations.
Incident Response & Operational Compliance Specialist at California Conservation Corps
December 1, 2021 - August 1, 2022
Deployed under tight timelines and strict emergency protocols to contain environmental threats, executing rigorous incident response workflows under high-pressure conditions. Supported boundary protection activities by constructing physical defense perimeters and containment lines using spatial risk assessment to shield high-value public assets from external threats. Ensured compliance with federal and state safety regulations (Cal/OSHA) by performing daily tactical gear and hazardous equipment validation checks to maintain a near-zero incident threshold.
Web Security & Full-Stack Developer at Colossians Mechanical
May 1, 2020 - October 1, 2024
Built and maintained custom web applications using Python, JavaScript, and TypeScript, implementing secure session handling and defenses such as CORS. Audited client-facing JavaScript/HTML/jQuery components to structurally eliminate DOM XSS and UI redirect-related vulnerabilities. Planned and developed responsive backend applications using AJAX/JSON, applying rigorous server-side checks to safely handle unstructured web input.
Logistics Operator & Risk Mitigation Specialist at Old Dominion Freight Line
October 1, 2018 - May 1, 2020
Managed physical security and authentication/identity verification processes, verifying credentials and manifests to prevent unauthorized personnel from accessing high-value asset boundaries. Enforced corporate and operational safety compliance frameworks, proactively identifying workplace hazards and performing immediate isolation procedures to mitigate operational risk. Used industrial scanning systems and databases to track, log, and audit freight routing paths, ensuring data integrity and helping prevent supply chain manipulation.
Software Engineer Intern at New Life Center
July 1, 2016 - May 1, 2020
Streamlined pipeline code maintenance by enforcing secure coding compliance frameworks, including static analysis standards and architecture best practices. Programmed comprehensive unit test suites using Python testing frameworks to detect runtime configuration errors and boundary logic errors prior to deployment. Refactored legacy backend data structures and optimization loops to improve web platform efficiency and memory safety.

Education

Non-degree technical track, Cybersecurity / Application Security (ongoing) at Application Security Academy
January 1, 2024 - September 22, 2026
Coursework / certificate (via edX/HarvardX) at CS50P (HarvardX / edX)
January 11, 2030 - September 22, 2026
Coursework / certificate (via edX) at EC-Council (edX / Modern States)
January 11, 2030 - September 22, 2026
Coursework (Modern States Education Alliance) at Modern States Education Alliance
January 11, 2030 - September 22, 2026
Coursework (C++) at Codio (c+ +)
January 11, 2030 - September 22, 2026

Qualifications

Add your qualifications or awards here.

Industry Experience

Software & Internet, Computers & Electronics, Government, Non-Profit Organization, Education