NJ.

Personal Dossier — Security & Engineering

Napon Jirapakatawee

Security Consultant · Penetration Tester · Builder

I break into web applications, networks, and mobile apps — legally — and write the reports that help teams fix what matters. 2,500+ professional hours across financial, insurance, and medical clients.

When I'm not on an engagement, I build things: full-stack apps, game-jam games, and an LLM agent that runs my digital life around the clock.

01 Profile

Offensive security,
full-stack foundations.

I'm a security consultant specializing in offensive security. For the past years I've run penetration tests and red team operations against web applications, network infrastructure, and mobile applications — blackbox and graybox — for clients in finance, insurance, and healthcare.

Before going on the offensive, I built things: full-stack web apps with MERN and Java Spring Boot microservices at IBM, data visualisation tooling for neural-network research in Germany, and more game-jam games than I can count. That engineering background is why I can read your code, not just your responses.

I also publish vulnerability research — CVE-2025-51962, an HTML injection in MicroStudio — and speak at community events, most recently a deep dive into CVE-2025-55182 ("React2Shell") at 2600TH × OWASP Bangkok.

Education
B.Eng Computer Engineering (Cyber Security)
Sirindhorn International Institute of Technology, Thammasat University — Class of 2024
GPA
3.66 / 4.00
Languages
Thai — native · English — C1 (IELTS 7.5)
Recent Talk
"React2Shell: The Lore Behind the Exploit"
2600TH × OWASP Bangkok Chapter — Feb 2026
Community
Thailand Cyber Top Talent 2023 — 27th of 354 teams
GDSC Thammasat — Head of Workshop Coordinator
02 Capabilities

What I bring to
an engagement.

No meters, no made-up percentages — just the work, and the tools it runs on.

Offensive Operations

Penetration testing and red team operations across web applications, network infrastructure, and mobile apps — blackbox and graybox engagements for clients where downtime is not an option.

Burp Pro · Nessus · Wireshark · Kali

Web & Mobile Assessment

Deep assessment practice across the full web attack surface — a certified Burp Suite Professional — plus Android tooling for mobile engagements, from static analysis to runtime instrumentation.

Frida · Objection · Jadx · Apktool / ADB

Engineering & Automation

Full-stack foundations from MERN to Java Spring Boot microservices built at IBM, plus LLM agent systems and workflow automation that run in production, around the clock, on my own infrastructure.

Python · Java · React · n8n / LLM agents

Research & Reporting

Published CVE researcher and conference speaker. Every engagement ends the way it should — a clear, professional technical report that your team can actually act on.

CVE-2025-51962 · OWASP BKK talk
03 Experience

Field notes.

Jul 2024 — Present

Security Consultant

Vantage Point Security (Thailand) Co., Ltd. · Bangkok

Penetration testing and red team operations for web applications, network infrastructure, and mobile applications across financial, insurance, and medical clients — each engagement closed with a professional technical report.

Jan 2024 — May 2024

Application Developer Intern

IBM Thailand Co., Ltd. · Bangkok

Built Java Spring Boot microservices for client applications, supporting backend teams on production-grade service development.

Jun 2023 — Jul 2023

Research Assistant Intern

Friedrich-Alexander-Universität Erlangen-Nürnberg · Germany

Visualised neural-network experiment data on GPU with Python (Flask) and D3.js / Plotly.js, and built the web GUI used to run and observe experiments. IAESTE Erlangen 2023.

2021

Full-stack Developer Intern

Advance Web Service PLC. · Bangkok

Developed and maintained web applications with HTML/CSS/JavaScript, React, MongoDB, Node-RED, and the LINE Front-end Framework.

05 Contact

Let's talk.

A security engagement, a collaboration, or a question about a report — my inbox is open, and I actually read it.