Security advisory and assurance

Pasin Visuttipinate

Also known as Ryo

Final-year computer science student in security, focused on turning technical findings into risk and recommendations a business can act on.

Hands-on with web application penetration testing

  • ISO/IEC 27001:2022
  • OWASP Top 10:2025
  • NIST CSF 2.0

View AuditYote Contact

About.

I am drawn to security advisory and assurance because it sits between two groups that often talk past each other: the people who find technical problems and the people who decide what to do about them. During my degree I met strong technical students who could not explain their work well, and strong communicators from my Business minor who had little technical grounding. Organizations have the same gap, and I am comfortable on both sides of it.

Most of my work so far has been hands-on. I have run authorized penetration tests on web applications and on IP cameras, and analyzed a ransomware sample as an incident report. Building AuditYote is what changed how I think about the field. I found I cared less about the code than about how an analyst would actually use it and how it would help a company run an audit. I try to write a finding so the same issue makes sense to an engineer and to a manager, and I think a lot of risk comes from controls that get skipped because nothing has gone wrong yet.

Featured projects.

  • The AuditYote findings dashboard, listing security findings with their severity, mapped controls, and workflow status.View full size

    AuditYote

    Live · Java, Spring Boot, React, PostgreSQL

    A full-stack governance, risk, and compliance app. It logs security findings, maps each one to ISO/IEC 27001:2022, OWASP Top 10:2025, and NIST CSF 2.0, and moves it through a role-gated review and sign-off workflow with separation of duties enforced on the server. It scores risk, tracks program-wide posture, keeps an audit trail, and exports CSV and PDF reports. Access runs through Spring Security with session authentication and role-based access control. The app is containerized, scanned in CI with Semgrep and Trivy, and deployed over HTTPS.

    The live site is open to explore. Demo logins for both the analyst and reviewer roles are on the sign-in screen.

  • The first page of a web application penetration test report on a UNION-based SQL injection, showing the executive summary and a findings table rating the issue critical at CVSS 9.8.View full size

    Security portfolio

    Authorized lab work

    Hands-on security work from authorized labs: web application penetration test reports, a ransomware incident analysis, and a mapping of the findings to ISO/IEC 27001:2022, OWASP Top 10:2025, and NIST CSF 2.0 controls. Each technical issue is restated as a control gap, a business risk, and a recommendation. This is the analysis that AuditYote turns into a workflow.

Skills and tools.

Security testing
  • Web application penetration testing
  • Vulnerability assessment and reporting
  • Malware and static analysis
  • Risk and control mapping
  • OSINT
Frameworks
  • ISO/IEC 27001:2022
  • OWASP Top 10:2025
  • NIST CSF 2.0
Tools
  • Burp Suite
  • Nmap
  • Wireshark
  • Metasploit
  • Kali Linux
  • VirusTotal
  • capa
Secure development
  • Java
  • Spring Boot
  • Spring Security
  • React
  • TypeScript
  • PostgreSQL
  • Docker
  • GitHub Actions
  • Semgrep
  • Trivy
  • Python

Experience.

Teaching

Mahidol University International College

Teaching assistant, computer science

Mahidol University International College · 2023–2026

I have been a teaching assistant for three core courses: Python, data structures and object-oriented programming in Java, and algorithms in Kotlin. I mentored students one on one outside class and graded work for cohorts of around forty. The job is mostly about explaining hard ideas clearly and marking to a consistent standard.

Training and certifications.

  • TryHackMe certificate of completion for the Jr Penetration Tester learning path, dated 2 December 2025.View full size

    Jr Penetration Tester learning path

    TryHackMe · Completed training · 2025

    Rooms across web exploitation, privilege escalation, Active Directory, and defensive operations. Thirty hours of guided practical work, not an examined certification.

    Certificate ID: THM-NV3COR8Y41

  • Cisco Networking Academy certificate for completing the Networking Basics course, dated 29 September 2025.View full size

    Networking Basics

    Cisco Networking Academy · Completed course · 2025

    Foundations of addressing, routing, and switching, taken through the Cisco Networking Academy program.

    Completed: 29 September 2025

Planned

  • CompTIA Security+ · Planned
  • ISC2 Certified in Cybersecurity · Planned

Contact.

I am looking for a security internship where I can work on real systems and see how an experienced team operates. Email is the best way to reach me.