
Hi, I’m Mike Broomfield, an experienced cybersecurity leader with around 20 years of hands-on experience spanning consultancies, global financial institutions, and large-scale enterprises. My career has taken me from penetration testing and security architecture roles at leading consultancies and major banks to my current position as Head of Application Security & Security Testing at Tesco. I have a deep passion for security research and engineering innovation, with a focus on embedding security seamlessly into modern software delivery. Over the years, I’ve led initiatives that integrate security into CI/CD pipelines, automate developer guardrails, and strengthen the resilience of complex, cloud-native systems. My approach blends a developer-first mindset with a curiosity for how systems fail and how they can be built stronger.
Hi, I’m Mike Broomfield, an experienced cybersecurity leader with around 20 years of hands-on experience spanning consultancies, global financial institutions, and large-scale enterprises. My career has taken me from penetration testing and security architecture roles at leading consultancies and major banks to my current position as Head of Application Security & Security Testing at Tesco.
I have a deep passion for security research and engineering innovation, with a focus on embedding security seamlessly into modern software delivery. Over the years, I’ve led initiatives that integrate security into CI/CD pipelines, automate developer guardrails, and strengthen the resilience of complex, cloud-native systems. My approach blends a developer-first mindset with a curiosity for how systems fail and how they can be built stronger.
Why I Started This Blog
Like many in our field, I’m constantly reading about new security techniques, tools, and methodologies, but I’ve found that real learning happens through doing. This blog is my way of keeping my technical skills sharp and holding myself accountable to keep exploring, experimenting, and learning in my spare time.
Here, I’ll be sharing my application security research, experiments, and observations. Expect a mix of practical write-ups, tool reviews, and deep dives into real-world security scenarios. While I’ll cover a broad range of topics, I’ll be placing a special focus on mobile and API security, two areas I’m particularly passionate about.
What to Expect
Hands-on walkthroughs of tools, frameworks, and techniques
Exploration of mobile and API attack surfaces
Practical examples of secure design and remediation patterns
Reflections on trends and challenges in the AppSec world
Ultimately, this blog is as much about sharing knowledge as it is about staying curious. My hope is that others who share a similar passion for security research will find something useful here — and maybe even join the conversation.
Thanks for stopping by and welcome to the journey.





