Jay Srinivasan

Security engineer · technical writer

I built a deliberately vulnerable application, then ran it through a full security pipeline — SAST, SCA, DAST, threat modeling, risk scoring, remediation.

The default scan configuration surfaced 7 of the 18 issues that a local run with custom rules and cross-file analysis found. Same tool, same codebase.

Had I trusted the default, I would have shipped an application I believed was clean. I wrote the whole thing up, and it became a six-part email course.

I build technical email courses for security companies.

Most technical marketing lands in one of two ditches: vendor language with nothing practical in it, or a specification document nobody finishes. I write the thing in between.

I can read your documentation, test the product, and talk to your engineers without marketing having to translate anything first — because this is my day job.

The service

Technical email course

A five-to-seven lesson course for your audience, about your product

You get the strategy, the research, the lessons, and everything needed to launch it:

  • Topic and audience strategy, built around one clear reader action
  • Product research — documentation, architecture, hands-on testing where access allows
  • Five to seven technically reviewed lessons, with code, checklists, or diagrams where they help
  • Landing page and welcome email copy
  • A closing lesson that leads to a trial, demo, or conversation without reading as a pitch

The shape of it: I learn the product, build the sequence, and hand you publication-ready lessons you can load into your own email platform. Two to three weeks, typically.

Who I build these for

Companies with a technically strong product and a hard time explaining it to the engineers who'd buy it:

  • Application security and software supply-chain vendors
  • SAST, SCA, DAST, and ASPM platforms
  • Identity, workload-identity, and secrets management
  • Cloud security, API security, and platform engineering tools
  • QA and software testing platforms moving into security
  • AI-security and LLM-safety vendors
  • Technical marketing agencies with security clients

See how I build one

Break It, Then Fix It

A free six-part course built from the project above — for developers and security practitioners who want to know what scanners find, what they miss, and how to turn findings into work that actually gets done.

  1. Why I built something deliberately broken
  2. What three scanners found — and what the defaults missed
  3. Threat modeling without the ceremony
  4. Risk scoring that survives a real backlog
  5. Remediation, with before-and-after code
  6. The whole pipeline as a repeatable checklist

Start the free course

One lesson every two days. Free, unsubscribe any time. Sign up and you'll see exactly what I'd build for you.

Things I've built

SIGINT

A security newspaper that reads arXiv, Hacker News, and CISA's exploited-vulnerabilities catalog every day, scores each item for novelty and actionability against a rubric I tuned by hand, and flags when something it covered earlier turns up as actively exploited in the wild. Go, no framework, runs on a cron for a few dollars a month.

Planning a technical education campaign?

Send me the product, the audience, and what you want readers to do at the end. I'll come back with a course angle and a lesson outline — no charge for that part.

Email me