Threat Modeling Before Build-Time Drift
Turning architecture questions into practical abuse-case decisions before risky assumptions become expensive rework.
Software Engineer Application Security Engineer
I’m Luka Golubović, a software engineer shaping my work around application security, secure delivery, and product security thinking. This site brings together the projects, experience, and engineering context behind that direction.
Security Focus
I’m most interested in the parts of security that improve shipping quality: clearer trust boundaries, safer defaults, and better decision-making before vulnerabilities become incidents.
Turning architecture questions into practical abuse-case decisions before risky assumptions become expensive rework.
Embedding validation, dependency hygiene, and policy guardrails into delivery flows without slowing teams to a crawl.
Focusing on trust boundaries, authorization decisions, and resilient backend design across modern service architectures.
Featured Work
2023-2024 A JavaFX desktop application for credential management with master-password authentication, persistent storage, and documented software architecture.
Credential protection, secure authentication flow design, and safe local persistence.
Open case study
2024-2025 A distributed chat system built with Go, React, and Redis pub/sub to study horizontal scaling of WebSocket connections, including a custom load balancer and containerized deployment.
Securing real-time communication channels and controlling trust boundaries across distributed services.
Open case study
2025 A personal local-first assistant platform where data stays on user-controlled infrastructure, built with FastAPI, ChromaDB, Vue 3, and Ollama. The project is still in active development.
Privacy-preserving architecture and local deployment safety for data-sensitive assistant workflows.
Open case studyNavigate
Connect
If you want to discuss AppSec, secure engineering, or one of the systems on this site, the fastest path is email or LinkedIn.