Summary
Overview
Work History
Education
Skills
Open-Source Contributor – GP2040-CE Project
Security Researcher – Dunkin's Summer 2022 Instant Win Game Self-Project
Security Researcher – Dick's Sporting Goods Reward Points System Self-Project | July 2024
Security Researcher – Albertsons Reward Points System Self-Project | April 2024
Security Researcher – Abercrombie & Fitch Reward System Self-Project | August 2024
Hardware & Software Developer – Custom Game Controllers Self-Project | October 2023
Timeline
Generic

Brian Mata

El Paso,TX

Summary

Motivated junior developer with a strong educational and practical background in development. Utilizes technical and programming knowledge to build and enhance successful applications across multiple languages.

Overview

4
4
years of professional experience

Work History

Junior Developer

Sauce Servers
San Francisco, CA
05.2021 - Current
  • Front-End Developer – Proxmox Custom Interface with WHMCS and Squid Proxy Automation
  • Integrated Proxmox with WHMCS to automate customer billing, account provisioning, and payment processing.
  • Implemented an automated system for deploying proxies using Squid within the Proxmox environment, allowing for efficient scaling and management of proxy servers.
  • Designed an automated workflow for proxy deployment, reducing manual setup time and increasing operational efficiency.
  • Ensured compliance with security best practices for API communication and payment processing.

IT SPECIALIST

PREBYSTERIAN HEALTH CARE
Albuquerque, NM
02.2024 - 11.2024
  • Assisted in the implementation of new technologies and systems to improve efficiency.
  • Performed routine maintenance on various IT equipment including computers and servers.
  • Delivered technical assistance to end-users encountering software or hardware glitches.

Education

Bachelor of Science - Computer Science

The University of Texas At El Paso
El Paso, TX
12-2024

Associate of Science - Computer Science

El Paso Community College
El Paso, TX
07-2020

Associate of Arts - Multidisciplinary Studies

El Paso Community College
El Paso, TX
07-2020

Skills

Programming Languages:

  • Proficient: Java, JavaScript, Python, GO, HTML, CSS
  • Familiar: C, PHP

Web Development:

  • Front-End: React, Svelte, Vuejs
  • Back-End: Nodejs, Expressjs
  • Databases: MySQL, MongoDB, PostgreSQL, Firebase

Version Control:

  • Git
  • GitHub
  • GitLab

Frameworks & Libraries:

  • Tailwind CSS
  • Bootstrap
  • jQuery

Responsive Design:

  • Mobile-first development
  • Cross-browser compatibility
  • Development Tools
  • Visual Studio Code
  • Docker, npm, Yarn

Debugging & Testing:

  • Unit testing
  • Jest
  • Mocha
  • Debugging with browser dev tools

Cybersecurity Skills:

Ethical Hacking Tools:

  • Nmap, Wireshark, Burp Suite, Metasploit, John the Ripper, OWASP ZAP

Penetration Testing:

  • Vulnerability scanning, System hardening, Threat modeling, Social engineering awareness

Network Security:

  • Firewalls, Intrusion Detection Systems (IDS), VPNs, Proxy Servers (Squid)

Operating Systems:

  • Linux (Kali, Ubuntu), Windows Server, macOS security features

Cryptography:

  • Encryption algorithms (AES, RSA), Hashing (SHA, MD5), PKI infrastructure

Web Application Security:

  • SQL Injection, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF)

Incident Response:

  • Malware analysis, Forensic investigation, Threat mitigation strategies

Risk Management:

  • Vulnerability management, Security audits, Mitigating DDoS attacks

Automation & Scripting:

  • Bash, Python, PowerShell for automating security tasks

Open-Source Contributor – GP2040-CE Project

  • Contributed to the development of the built-in web-based configuration for GP2040-CE, an open-source firmware for gamepads and custom controllers.
  • Submitted a successful pull request to improve the usability and functionality of the web interface, enabling users to configure gamepad settings directly through a browser.
  • Collaborated with other developers to refine user experience and ensure efficient handling of real-time configuration changes.
  • Worked with technologies such as HTML, JavaScript, and CSS to optimize the front-end interface and ensure cross-browser compatibility.

Security Researcher – Dunkin's Summer 2022 Instant Win Game Self-Project

  • Identified and reported security vulnerabilities in Dunkin's Summer Instant Win game by automating the testing and validation of game mechanics and server responses.
  • Utilized custom automation scripts to detect weaknesses in the game’s backend, exposing potential exploits related to prize distribution and game logic.
  • Demonstrated ethical hacking principles by documenting the vulnerabilities and reporting them to the relevant company, ensuring responsible disclosure.
  • Employed custom Python scripts, and Go scripts to simulate user behavior and analyze server responses in real-time.
  • Provided recommendations for securing the game’s systems, protecting user data, and preventing exploitation of game mechanics.

Security Researcher – Dick's Sporting Goods Reward Points System Self-Project | July 2024

  • Discovered security vulnerabilities in Dick's Sporting Goods reward points reclaim system, allowing unauthorized access to guest order information.
  • Identified that the system’s response contained excessive data, which exposed sensitive guest order details, potentially enabling the exploitation of other users’ orders.
  • Utilized tools such as Postman and custom automation scripts to analyze request-response patterns and demonstrate the security flaw.
  • Reported findings to the appropriate parties, ensuring responsible disclosure of the vulnerability and recommending security enhancements to prevent unauthorized access.
  • Suggested improvements in the handling of guest order data, including limiting the information exposed in API responses and strengthening authentication mechanisms.

Security Researcher – Albertsons Reward Points System Self-Project | April 2024

  • Identified a vulnerability in Albertsons' reward points system, where repeated requests (spamming) could exploit the system to earn unauthorized reward points.
  • Used automation tools and custom scripts to send multiple rapid requests, demonstrating how the flaw could be used to accumulate more points than the system intended.
  • Performed analysis on the API responses, identifying weak rate-limiting controls and insufficient validation of reward point transactions.
  • Responsible for documenting and reporting the vulnerability to Albertsons, ensuring ethical disclosure to prevent malicious exploitation.
  • Provided recommendations to improve security, including implementing rate-limiting and stricter request validation to protect against reward point abuse.

Security Researcher – Abercrombie & Fitch Reward System Self-Project | August 2024

  • Discovered a vulnerability in Abercrombie & Fitch's reward system that allowed brute-forcing of guest order numbers, leading to unauthorized reclamation of reward points.
  • Demonstrated how systematically generating and submitting order numbers could be exploited to claim extra points without legitimate purchases.
  • Used tools like Postman and custom automation scripts to automate brute-force attempts, revealing weaknesses in the system's verification process.
  • Documented and responsibly reported the vulnerability, recommending improvements in authentication and order number validation to prevent unauthorized access.
  • Provided suggestions for security enhancements, including rate-limiting, CAPTCHA, and stronger order number entropy to safeguard the reward points system.

Hardware & Software Developer – Custom Game Controllers Self-Project | October 2023

  • Designed and built custom game controllers using Fusion 360 for 3D modeling and KiCad for PCB design, integrating with GP2040-CE firmware for advanced functionality.
  • 3D printed controller housings using Bambu Lab 3D printers and resin printers, ensuring high-quality, durable, and ergonomic designs.
  • Cut and crimped custom wiring to connect internal components, ensuring precise and reliable electrical connections.
  • Developed PCB layouts to accommodate custom hardware, optimizing for performance, assembly, and integration with 3D-printed enclosures.
  • Programmed and configured controllers using the open-source GP2040-CE firmware, enabling advanced input customization and functionality.
  • Collaborated with the open-source community to refine the GP2040-CE software, ensuring seamless integration with custom hardware.

Timeline

IT SPECIALIST

PREBYSTERIAN HEALTH CARE
02.2024 - 11.2024

Junior Developer

Sauce Servers
05.2021 - Current

Bachelor of Science - Computer Science

The University of Texas At El Paso

Associate of Science - Computer Science

El Paso Community College

Associate of Arts - Multidisciplinary Studies

El Paso Community College
Brian Mata