Skip to content
Get in touch

Honolulu, Hawai'i

Blaise Aranador

I'm Blaise, a digital network exploitation analyst from Honolulu, Hawai'i, working at the intersection of building software and breaking it. My day-to-day is reverse engineering, vulnerability research, and building tools that show teams what their code is really doing. I like the problems where the answer isn't on the first page of the docs.

Lately I've been leaning further into offensive security, and I hold TCM Security's Practical Network Penetration Tester (PNPT) certification. Outside of that, most of my coding time goes toward building automation that streamlines day-to-day operations for real businesses.

Off the clock you'll usually find me at the golf course, where I both work and play. Downtime is simple: code, golf, paddle boarding over the reef to check on the fish, and catching up on sleep.

Thanks for stopping by — if you want to talk shop, trade ideas, or swap fish stories, the contact form is at the bottom. I read everything.

Things I've built

Real problems, for real people — what the thing fixed, not what it was written in.

Invictus

The site you're looking at. A portfolio built with Next.js, TypeScript and Tailwind — an island palette with dark, light and system themes, and a ⌘K palette that answers questions in plain English from the site's own content. Under the hood it takes the engineering as seriously as the design: a strict Content-Security-Policy, rate-limited APIs, a content pipeline that keeps personal data out of both the repository and the published image, and a CI/CD pipeline that ships a Docker image behind nginx with automatic TLS.

Visit Invictus

FloOps

FloOps is a full-stack operations management platform for golf courses. Superintendents and crews use it to plan daily tasks, track equipment and work orders, manage timesheets and crew assignments, and pull operational reports. The platform spans three components — a Next.js web app, an Expo/React Native mobile app, and a FastAPI + PostgreSQL backend — built as a multi-tenant SaaS with role-based access control, Stripe subscription billing, and JWT auth with server-side token revocation.

Visit FloOps

Carnegie Mellon University Bomb Lab

Reverse-engineered CMU's Bomb Lab binary — a staged puzzle that "explodes" on wrong input — using IDA Free and GDB with PEDA. Worked phase by phase through the disassembly to reconstruct each check's logic and derive the exact inputs needed to defuse it.

Visit Carnegie Mellon University Bomb Lab

Clarity

Clarity is a lightweight digital-signage system built for a golf course maintenance crew: a Python service on a Raspberry Pi 4 that watches a Google Drive folder through the Drive API, pulls the latest PowerPoint or video, and displays it full-screen until a new file is uploaded. It replaced the daily routine of loading media onto a USB drive and carrying it out to the crew monitor — saving my client ten minutes every day and keeping schedules and announcements always current.

Visit Clarity

Where I have worked

The long version, for the people who need the long version.

Digital Network Exploitation Analyst, Team Lead

Department of Defense

07/2024 – PRESENT

  • Python
  • Reverse Engineering
  • Vulnerability Research
  • Led a software analysis team in conducting comprehensive vulnerability research, identifying exploitable weaknesses in target software through meticulous examination and strategic planning.
  • Efficiently identified a handful of potentially vulnerable software daily by analyzing extensive lists of hundreds of programs, enabling vulnerability researchers to save 30 hours of weekly analysis and focus their efforts on in-depth reverse engineering, resulting in a 10% increase in identified vulnerabilities.
  • Prepared and delivered presentations, and assisted with detailed reports for senior stakeholders, relaying critical findings to facilitate tactical and strategic decisions aimed at strengthening our cyber security posture.
  • Coordinated the onboarding process for several new team members, ensuring they were equipped with all necessary tools and had a thorough understanding of operational procedures critical for conducting vulnerability research and exploitation development.

Greenskeeper

Waialae Country Club

11/2024 – PRESENT

  • Maintained pristine bunker conditions to championship standards at Waialae Country Club, host of the PGA Tour's Sony Open in Hawai'i.
  • Supported daily course preparation at a Platinum Club of America and Distinguished Club with ELITE status, ensuring top-tier playability.
  • Delivered consistent, high-quality groundskeeping in a fast-paced, team-oriented environment serving private club members and professionals.

Software Engineer

Department of Defense

08/2021 – 06/2024

  • Python
  • Docker
  • JavaScript
  • Jenkins
  • Sonarqube
  • Led multiple projects as team lead, automating analysts' manually intensive workflows for various organizations — including streamlining data acquisition, processing, report generation, and data delivery to deployed personnel, enabling analysts to reclaim up to 30% of their time for high-priority mission needs.
  • Leveraged CI/CD tools such as Jenkins and GitLab CI/CD pipelines to continuously deploy secure, compliant, and sustainable software solutions, ensuring timely and efficient delivery to customers.
  • Briefed the Director and senior leadership on emerging projects, highlighting how our team's innovations significantly enhanced the efficiency of analysts' workflows, thereby positively impacting organizational productivity.
  • Co-led a training program to educate peers on the software development cycle, basic coding skills, and automation technologies, empowering them to streamline their manually intensive processes.
  • Volunteered at a higher education institution to mentor students pursuing careers in the field by sharing my knowledge and expertise, assisting them in discovering new opportunities, and providing guidance on transitioning from student to full-time worker.

Software Developer Intern

Department of Defense

06/2019 – 09/2019

  • Python
  • Docker
  • Git
  • Jenkins
  • Sonarqube
  • Designed and developed secure and compliant solutions to meet both tactical and strategic mission needs, ensuring corporate sustainability.
  • Created a Python web-based application that automated several manually intensive processes, significantly enhancing analysts' productivity and enabling accurate data delivery to deployed personnel.
  • Adapted to the Agile software development paradigm, effectively automating the building, packaging, and delivery of software to the customer.

What I work with

Grouped by what it's for, so you can find what you're looking for quickly.

Languages

  • Python
  • C++
  • JavaScript
  • SQL
  • Bash

Web

  • NextJS
  • HTML
  • CSS

Infrastructure

  • Git
  • Docker
  • Jenkins
  • Nginx
  • Sonarqube
  • Kubernetes

Security

  • Ethical Hacking
  • Hack The Box

What I'm digging into now

Not finished work — the things I'm actively building with. Honest about where each one is.

Live on this site

Search that understands questions

The ⌘K bar reads questions rather than matching keywords. Ask whether I know Docker, or whether I could build you a booking system — it answers from my own content, then takes you there.

Development

AIfred

Turf and agronomy management for golf course superintendents. A crew member photographs a green from their phone, or a programmed drone flies a fairway. AIfred assesses the turf, cross-references weather-driven disease pressure, and returns a ranked action plan — with the evidence behind every recommendation. The point is not to describe photographs. It is to act before the problem is visible.

Development

Kairos

A Python framework that turns a complete price-action trading course — risk management, execution and trade management, psychology, and trading styles — into a working decision-support system. New material extends it without rewrites, and a guardrailed feedback loop adapts its parameters from the trader's own realized results over time.

How working together goes

No mystery, no black box. Here's the whole process before you commit to anything.

  1. 01

    You tell me the problem

    In your words. No technical vocabulary required — that's my job, not yours.

  2. 02

    I scope it honestly

    A fixed price and timeline — including telling you if you don't actually need me.

  3. 03

    You see it every week

    Something working in your hands each week, so nothing is a surprise at the end.

  4. 04

    You own it

    Code, accounts and documentation handed over. No lock-in, no hostage situation.

Got something that needs building?

Tell me the problem in your own words. I'll tell you straight whether I can help.

Start a conversation

Let's Connect.