About Me
I'm Milan, an Application Security Engineer with over 20 years of software development experience. I spent most of my career building enterprise Java applications before making a deliberate move into application security. That background shapes everything I write here.
Security advice that ignores how development teams actually work tends to get ignored right back. Because I've been on the development side for a long time, I focus on security guidance that fits into real workflows and real codebases. When I explain a vulnerability, I also explain why the insecure pattern felt reasonable to the developer who wrote it and what the secure alternative looks like in practice.
This blog covers web application security topics with a focus on the OWASP Top 10, secure coding patterns in Java and Spring, and the architectural thinking behind effective security programs. Most articles follow a consistent structure: vulnerable code, an explanation of what goes wrong and why, then a secure implementation with the reasoning behind each decision. Also, there are articles that touch same vulnerabilities from the security architect point of view.
The content is written for intermediate and senior developers who want to build more secure applications, and for junior and intermediate application security engineers who want to deepen their technical foundation.
If you want to connect, you can find me on LinkedIn.

