Skip to content

Selwyn UyFull Stack Next.js Web Developer

I build web apps that are secure before they're anything else.

Full-stack Next.js engineering with a security background, so the things most teams patch later, I get right from the first commit.

selwyn@portfolio:~

$ whoami

Full Stack Next.js Web Developer

$ cat stack.txt

Next.js React TypeScript Node.js PostgreSQL Supabase

● Available for work

Status
Open to roles
Shipped
cseexamreview.com

02The story

Why secure by default

  1. The origin

    I came to development from security.

    Before I was shipping features, I was thinking about how systems break, how data leaks, how auth gets bypassed, how an innocent input becomes an exploit. That lens never switched off when I started building products.

  2. The approach

    So I build the opposite way most teams do.

    Security usually gets bolted on at the end, under deadline pressure. I start there: validated inputs, least-privilege access, and secrets that never touch the client, baked in from the first commit, not retrofitted after an audit.

  3. What it means for you

    You get full-stack speed without the security debt.

    I deliver complete Next.js products, database to deployed, that are fast and well-built, and that don't hand your team a backlog of vulnerabilities to clean up later.

  • Next.js
  • React
  • TypeScript
  • Node.js
  • PostgreSQL
  • Supabase
  • Tailwind CSS
  • Auth.js
  • Next.js
  • React
  • TypeScript
  • Node.js
  • PostgreSQL
  • Supabase
  • Tailwind CSS
  • Auth.js
  • Zod
  • Vercel
  • Web Security
  • OWASP Top 10
  • Penetration Testing
  • Burp Suite
  • Threat Hunting
  • Zod
  • Vercel
  • Web Security
  • OWASP Top 10
  • Penetration Testing
  • Burp Suite
  • Threat Hunting

03Selected Work

Projects

The proof. Each of these shipped, here's what they did, not just what they used.

01

CSE Exam Review

A platform I founded to help people prepare for the Civil Service Exam. Built and shipped end to end on Next.js, from the database to deployment, with authentication and content delivery handled securely.

  • Next.js
  • TypeScript
  • PostgreSQL
  • Tailwind
  • Auth
02

ReservePolomolok

A local booking platform for Polomolok, South Cotabato: real-time availability, deposit-based reservations to cut no-shows, and a unified calendar so business owners manage online and walk-in bookings from one place. Live for sports court rentals, with venues, resorts, and salons launching next.

  • Next.js
  • TypeScript
  • Supabase
  • Tailwind

04The Handbook

How I actually build

Not just what I shipped, but how. Read the fact-checked field guide, or install my actual process straight into your own AI.

44 pages, and growing

From the first commit to deployment: project setup, security by default, the integrations I reach for, and how I ship. Every page is verified against the current Next.js docs.

  • Start Here
  • Architecture
  • Design
  • Build
  • Security
  • Grow
  • Ship
  • Operate

14 installable skills

Want it to just do it? Install my process as a Claude Code skill, the discovery-to-PRD workflow, the anti-slop check, the Next.js scaffold, and your agent runs it the way I would.

  • Discovery to PRD
  • Anti-Slop Check
  • Brand Voice
  • Bootstrap Next.js
  • Next.js 16 Facts
  • Next.js Security Audit
  • Verify Before Ship
  • Review Before Commit
  • SEO Audit
  • Launch Checklist Run
  • AI Legibility Audit
  • Session Continuity
  • Architecture Decision Log
  • PDF Generator

05Background

Experience

The track record, where I've built and what I owned.

  1. Founder and Full Stack Developer

    2026, Present

    cseexamreview.com (Self-employed)

    • Founded and shipped cseexamreview.com end to end on Next.js, a Civil Service Exam prep platform built from database design through production deployment.
    • Owned the auth and data layer with a security-first posture: validated inputs, least-privilege access, and secrets kept off the client.
    • Run the full lifecycle solo, architecture, build, and release, shipping continuously.
  2. Web Developer

    2026, Present

    Forthwith Industry LLC

    • Build and ship production Next.js applications (App Router, Server Components) in TypeScript for a US-based team, remote.
    • Implement authentication, middleware, and server actions with least-privilege access across administrative routes.
    • Apply Security-by-Design defaults, strict input validation, CSP, and secure HTTP headers, to harden against OWASP Top 10 risks.
  3. Cybersecurity Intern (VAPT)

    2026

    Black Bear Securities

    • Ran vulnerability assessments across web applications and APIs using OWASP methodologies, identifying and reporting high-severity findings.
    • Validated exploitability with manual and automated testing and wrote proof-of-concept exploits to help engineering prioritize remediation.
    • Delivered technical reports and executive summaries, then verified that hardening controls (auth hardening, input validation, CSP) were correctly implemented.
Download resume ↓

06Credentials

Certifications

The receipts behind the security claim. Credentials, not adjectives.

07Contact

Let's build something.

Have a role, project, or idea in mind? Send a message and I'll get back to you. Or reach me directly at selwyn.cybersec@gmail.com.

South Cotabato, PH · Remote