⬇ Download PDF ⬇ Word
Khaleb George
(they/them)
3134 rue Dandurand, Montreal, QC, H1Y 1V1
(438) 993-5369
aubainekyrian@proton.me
Portfolio: codeberg.org/Caemulus/code-review-portfolio
PROFESSIONAL SUMMARY
Software and security professional delivering production-grade work: code review, backend security testing and auditing, full-stack development, HTML5 game development and game audio.
Every deliverable is tested and security-checked before handoff, with findings reported as file:line evidence, severity ratings and a concrete fix plan. I direct a set of AI specialists and own the result: work passes a machine-enforced, two-auditor review before it ships, and I am accountable for whatever is handed over.
SKILL SET
- Machine-enforced audit gate — every deliverable passes a two-auditor, four-pass review against a committed audit artifact before it can ship. The gate refuses to release code without a sign-off covering that exact code tree
- Security code review & vulnerability auditing — file:line evidence, severity ratings, fix plans
- Backend security testing — authentication, sessions, authorization, rate limiting, input validation, secret handling, endpoint exposure
- Dependency & supply-chain review — Semgrep, Trivy, Gitleaks, osv-scanner, SBOM pipelines
- Production hardening — exposure analysis, leak remediation, git-history purging, verified from a clean clone
- Full-stack development — Cloudflare Workers, D1, KV; auth, sessions, leaderboards
- HTML5 game development — original art and procedural music, portal-ready packaging
- Game audio engineering — adaptive WebAudio synthesis, arrangement, SFX palettes
- Deliverables in English, French, German and Spanish — reports, documentation, UI text and code comments
CODE LANGUAGES
- JavaScript — 37 shipped HTML5 games, procedural WebAudio music engine, browser and Node tooling
- TypeScript — Cloudflare Workers backend (authentication, sessions, leaderboards), strict typing
- HTML5 & CSS — game interfaces, responsive layouts, canvas rendering
- Node.js — build, packaging and release CLIs; zero-dependency tooling
- SQL — D1/SQLite schema design and queries for the production account platform
- Shell — Bash and PowerShell automation, cross-platform build scripts
RELEVANT EXPERIENCE
- Published third-party security review of psf/httpbin: 1 High (CORS reflect-plus-credentials), 4 Medium and 5 Low findings — every one with file:line evidence, publicly verifiable
- Built a machine-enforced release gate: two independent auditors, four review passes, and no release without a signed audit artifact covering the exact code revision. Verified against nine test cases.
- Found and remediated a live exposure in a public repository — reconnaissance data served at a public URL. Fixed at the tip, purged from full git history across every branch, verified from a clean clone.
- Adversarially reviewed a security gate and found two real defects, including one that would have blocked every legitimate release permanently.
- Production account backend on Cloudflare Workers + D1 + KV: authentication, sessions, leaderboards. 16/16 integration tests passing against the live production deployment.
- 37 HTML5 games built, packaged and shipped live — verified zips, per-game metadata, portal-ready
- Procedural music engine: 50+ deployed game themes, zero audio files, zero dependencies
LANGUAGES
Fluent: English / French
Currently learning: Spanish / Japanese
HOW I DISCLOSE AI
I use AI specialists to produce work, under my direction, with a machine-enforced audit before anything ships. I own and am accountable for every deliverable. If you would prefer work produced without AI, tell me before the order and I will say honestly whether I am the right fit.
WORKING TERMS
- Honest findings only — no inflated severity, no invented vulnerabilities
- Client code stays isolated and is never retained after delivery
- Only open-source reviews are published as public samples
- Every deliverable is security-checked before handoff