Filip Dobrev

Software that holds up after it ships.

One engineer who builds it, improves how you ship it, and reviews its security. Prices are published below.

Worked at Uber TU Delft It Goes Forward Vera Connect

Three ways this usually starts

It does not exist yet

Build

From a marketing site to the first version of a product. You get the repository, the pipeline and the documentation, and it ships running rather than nearly running.

See what building costs

It works, but it costs the team time

Improve

The deploy that eats an evening, the spreadsheet somebody rebuilds every Monday, the outage your customers report before you notice. Ranked by hours saved per month.

See what improving costs

It is live and you are worried

Review

What an attacker sees, where your keys live, what one codebase actually gets wrong, and where your users get stuck. Findings ranked by business impact, each with the fix written out.

See what reviewing costs

Most people who build software have never attacked any. Most people who attack it have never had to ship. I do both.

Services & Prices

All fourteen, priced. Tick what you need.

Every price is days × day rate
€350 – 550 per day

Ranges are honest, not anchors. The scope call turns a range into one number, and that number goes in the written brief before anything starts.

Ongoing, not per project

Retained upkeep

€100 – 350 / month

Dependency and security updates, certificate and backup checks, uptime monitoring, and a person who already knows your system when something breaks.

Embedded with your team

€350 – 550 / day

Booked days inside your team, your board and your standups. For when the work is continuous and a fixed scope would only get in the way.

Both are kept out of the scope builder on purpose. A monthly retainer and a day rate are not project costs, and adding them to a project total would only make the number wrong.

Six steps, and you can leave after the first

  1. Step 01

    Scope call. Thirty minutes, free.

    What you have, what you need, and what a good outcome looks like. If I am the wrong person, I say so on this call.

  2. Step 02

    Written brief.

    What is being built, improved or tested, what is explicitly out of scope, the timeline, the price and who decides. Security work includes signed authorization.

  3. Step 03

    The work.

    Weekly written updates on builds, a halfway update on reviews. Anything critical reaches you the hour I find it.

  4. Step 04

    Delivery.

    Builds ship running, with the repository, pipeline and documentation in your hands. Reviews ship as a report ranked by business impact, each finding with the fix written out.

  5. Step 05

    Walkthrough. An hour, live.

    A handover for builds, a findings walkthrough for reviews, while the context is still fresh in both our heads.

  6. Step 06

    Aftercare. Thirty days.

    Fixes on anything I built that does not behave as agreed. For reviews, a free retest of every finding you fix inside that window.

Before you email

What I don’t do

Some of this costs me work. I would rather lose the wrong project than take it and disappoint you halfway through.

I don’t call a code review a penetration test.

They find different things. A review reads the code and the configuration. A pentest attacks a running system under agreed rules. If you need one signed off for a customer or an auditor, say so and I will point you at someone who does them properly.

I don’t forward scanner output and call it a report.

Any tool can produce the raw list in an afternoon. Working out which findings are genuinely exploitable in your system, and which are noise, is the part you are actually paying for.

I’ll need it in writing before I start testing.

Not because I am precious about paperwork. One page naming the systems, the window and someone to call if something goes sideways takes about ten minutes to agree, and it means neither of us is guessing later. Once it is signed I get going.

I don’t issue certificates.

I will do the legwork to get you ready for ISO 27001, a customer security questionnaire or an insurance renewal. The certificate itself comes from an accredited body. Anyone offering to issue it directly is not one.

I don’t hand your project to anyone else.

The person on the scope call is the person writing the code. Nothing goes to an agency bench, a junior, or a team you never meet.

I don’t quote a number I have not thought about.

If a scope is too vague to price, I say so and we spend the free call making it specific. A confident guess that doubles in month two helps neither of us.

Things I have actually shipped

2024 – 2026

Multi-tenant e-commerce returns platform

Founding engineer, from an empty repository to paying merchants. I built the API security, the multitenancy, and the GDPR privacy work that came with holding other companies’ customer data. Isolation was a database per tenant. It kept merchants apart, but it did not carry schema migrations cleanly across all of them, and that is the piece I would design differently now.

TENANT ATENANT BTENANT CTENANT D SHARED CORE DB ADB BDB CDB D
END OF LIFE AND CVE FLAGGED

2025

Network vulnerability scanner

Scans IP ranges, detects open services, extracts version information, and flags end-of-life software and known CVEs. I wrote it, so the exposure assessment I sell is not a rented tool with my name on the report.

YOU PHONEADDRESSCONTACTS A 2 OF 3 B 1 OF 3 SAME DATA, DIFFERENT PEOPLE

2023

Secure data-sharing social platform

Vera Connect. A social platform where you decide, per person, which parts of your data they get to see: phone number, address, date of birth, contacts. Shipped and live with real users on it. I did the privacy hardening and ran the database migrations against it in production. An end-to-end encryption prototype sat on top of that, built to test whether the model held.

PROBE LOSS, VALIDATED

2025 – 2026

Country-level internet outage detection

MSc thesis. Analyses RIPE Atlas probe traffic to detect national outages and then validate that what the data shows actually happened.

v1v2v3 BOTH VALID ROTATION, NO RESTART

Now

Platform security at Uber

Secrets rotation and handling, leak detection, identity and access management, secrets cryptography, and the site reliability side of keeping all of it running.

MSc Computer Science, Cyber SecurityTU Delft
BSc Computer Science & Engineering, Cum LaudeTU Delft
Teaching Assistant, CryptographyTU Delft
Tsinghua UniversityBeijing, China

Tell me what you have and what is worrying you.

filipdbrv@gmail.com
Day rate
€350 – 550
Reply
Within one working day
Based in
Delft, Netherlands
Works
Remote across Europe
Languages
Bulgarian, English
Elsewhere
LinkedIn, GitHub

    Retainers and booked days are priced separately and are not part of this total.