Working across medical terminology, standards research, and security as several clinical systems come together into one shared platform.
A hands-on assessment of a deliberately vulnerable banking app, finding the authorization and configuration weaknesses and writing up how to fix them.
Working a vulnerable API from its docs instead of a screen, reasoning about endpoints I could not see, the way real API testing often starts.