Profile photo
Aaron Anthony A. Gano II
Bambang, Philippines
Aspiring Purple-Team Security Engineer
About

I'm a fourth-year BS Computer Science (Robotics) student (irregular, SY 2026–27) working toward becoming a purple-team security engineer — someone fluent in both offense and defense. My approach to every project is the same loop: run a realistic attack, watch it from the defender's side, then write the detection that closes the gap.

I do most of my work from a computer shop here in Bambang, Nueva Vizcaya. I don't have a rig of my own yet, so I'm building a cybersecurity skill set on limited resources — free labs, open-source tools, and a lot of persistence. I'm saving up to fund paid certifications and build my own PC, partly through being outsourced by the Provincial Government of Nueva Vizcaya, working under the guidance of the PDRRMO on the One Vizcaya project.

Resource limits aside, I document every project as if it were a real engagement and publish it so it can be reviewed end to end. The goal is simple: let the work speak for itself, and keep climbing the certification roadmap toward OSCP.

Tech Stack

Cybersecurity

PythonBashPowerShellCC++Burp SuiteNmapWiresharkGhidraZero TrustISO 27001

Frontend

JavaScriptTypeScriptReactViteNext.jsTailwind CSSshadcn/ui

Backend

Node.jsHonoNestJSExpressREST APIJWTOAuth 2.0PostgreSQLMongoDB

Mobile

DartFlutter

DevOps / Cloud

AWSDockerKubernetesTerraformGitHub ActionsPrometheusGrafana

AI & Machine Learning

PyTorchscikit-learnTensorFlowOpenAI
Main Project
Experience
Oct 2025 — Present
Backend & Security Developer
One Vizcaya · Provincial Government of Nueva Vizcaya (PDRRMO)
Outsourced by the provincial government to build the backend and security layer of One Vizcaya — designing REST APIs, hardening authentication (JWT / OAuth), and protecting user data, under PDRRMO guidance.
Apr 2024 — Present
Self-Directed Cybersecurity Practitioner
Independent · Purple Team focus
Building offensive and defensive skills through hands-on labs, CTFs, and a documented project roadmap — working toward a purple-team security engineering role and the OSCP certification.
Security Project Roadmap

A purple-team build plan — red and blue projects across offense, defense, and general security. Each becomes its own documented repo as I complete it.

Focus area
All
Purple
Defense
Offense
General
Difficulty
All
Easy
Medium
Hard
Focused
Certifications

My certification roadmap, ordered by priority and cost — free wins first, then the credentials that prove I'm Purple, building toward OSCP.

Learning Journey

My self-directed path from CS student to Purple Team — a four-stage plan built on hands-on labs, not just checklists. The through-line is the Purple loop: run the attack, detect it, write the rule that catches it.

1
Build the Foundation
Networking, Linux, Python, and a home lab on hardware I own. Wireshark captures, living in the terminal, a hand-written port scanner, and popping my first box.
NetworkingLinuxPythonHome Lab
2
Red & Blue → Purple
Offense on TryHackMe & Hack The Box, defense on LetsDefend & Splunk, and web hacking via PortSwigger. Learning both sides together so every attack sharpens my defense.
TryHackMeHack The BoxSIEMWeb Hacking
3
Prove It — Certifications
Earning credentials that prove what the projects already show, picked up as their material lines up with what I'm practising. Security+ → CySA+ / eJPT → OSCP.
Security+eJPTCySA+OSCP
4
Get Hired — Portfolio & Job Hunt
Turning lab work into a visible portfolio: GitHub repos, writeups, CTFs, and applying to roles both local (PH) and remote — this site being part of that.
GitHubWriteupsCTFsPicoCTF
Social Links