Skip to main content

Command Palette

Search for a command to run...

Welcome to My Blog

Exploring the Art and Science of Application Security

Updated
View as Markdown
Welcome to My Blog
M

Hi, I’m Mike Broomfield, an experienced cybersecurity leader with around 20 years of hands-on experience spanning consultancies, global financial institutions, and large-scale enterprises. My career has taken me from penetration testing and security architecture roles at leading consultancies and major banks to my current position as Head of Application Security & Security Testing at Tesco. I have a deep passion for security research and engineering innovation, with a focus on embedding security seamlessly into modern software delivery. Over the years, I’ve led initiatives that integrate security into CI/CD pipelines, automate developer guardrails, and strengthen the resilience of complex, cloud-native systems. My approach blends a developer-first mindset with a curiosity for how systems fail and how they can be built stronger.

Hi, I’m Mike Broomfield, an experienced cybersecurity leader with around 20 years of hands-on experience spanning consultancies, global financial institutions, and large-scale enterprises. My career has taken me from penetration testing and security architecture roles at leading consultancies and major banks to my current position as Head of Application Security & Security Testing at Tesco.

I have a deep passion for security research and engineering innovation, with a focus on embedding security seamlessly into modern software delivery. Over the years, I’ve led initiatives that integrate security into CI/CD pipelines, automate developer guardrails, and strengthen the resilience of complex, cloud-native systems. My approach blends a developer-first mindset with a curiosity for how systems fail and how they can be built stronger.

Why I Started This Blog

Like many in our field, I’m constantly reading about new security techniques, tools, and methodologies, but I’ve found that real learning happens through doing. This blog is my way of keeping my technical skills sharp and holding myself accountable to keep exploring, experimenting, and learning in my spare time.

Here, I’ll be sharing my application security research, experiments, and observations. Expect a mix of practical write-ups, tool reviews, and deep dives into real-world security scenarios. While I’ll cover a broad range of topics, I’ll be placing a special focus on mobile and API security, two areas I’m particularly passionate about.

What to Expect

  • Hands-on walkthroughs of tools, frameworks, and techniques

  • Exploration of mobile and API attack surfaces

  • Practical examples of secure design and remediation patterns

  • Reflections on trends and challenges in the AppSec world

Ultimately, this blog is as much about sharing knowledge as it is about staying curious. My hope is that others who share a similar passion for security research will find something useful here — and maybe even join the conversation.

Thanks for stopping by and welcome to the journey.