I’m Eliran — a backend engineer at Microsoft, where I work on application security.

I spend my days helping teams build secure systems and thinking about how to make security knowledge practical and accessible for developers. Before that, I was a software engineer focused on distributed systems and backend architecture.

What I Write About

This blog is where I share what I learn at work and beyond. Most of my writing falls into:

  • Security for Builders — my flagship series making application security practical for software engineers. Covers CSRF, threat modeling, injection attacks, secrets management, and more.
  • Backend engineering — distributed systems, database pitfalls, idempotency, logging, testing practices.
  • Career & growth — honest lessons from my journey as a software engineer.

Beyond Work

Things I love:

  • my wife
  • coffee
  • playing table tennis
  • cooking
  • my dog (look at this cutie…)
    my dog

Stay in Touch

I send a short email when something new is published — no spam, unsubscribe anytime.

Subscribe to the newsletter →

Or reach me via Email / Twitter / LinkedIn