Independent Research  /  Vulnerability Disclosure  /  Since 1999
REF// IR-2026-0824
SubjectShawn
ClassificationPublic Profile
Status● Active — Accepting Engagements
LocationCanada
Independent Bug Bounty Researcher

Shawn

I find security flaws before attackers do — and report them responsibly. 25+ years across networking, systems administration, and information security back every engagement.

$
§01

Summary

I'm an independent security researcher. I find, verify, and responsibly disclose vulnerabilities in web applications, networks, and cloud infrastructure. Before bug bounty, I spent two and a half decades in IT — networking, systems administration, and security — so I'm not just testing apps, I understand the infrastructure they run on.

Most of my work is under NDA, so I can't share client names or specific findings — details withheld — but I hold every report to the same bar: reproducible, clearly written, real impact.

25+
Years across IT, networking & security
4
Major bug bounty platforms active on
§02

What is bug bounty research?

Definition

A bug bounty is a program run by a company or organization that invites independent researchers to legally search for security weaknesses in their systems — websites, apps, APIs, and infrastructure — and report them privately, before criminals find them first.

Instead of exploiting a flaw, a researcher documents it, proves it's real with a safe proof-of-concept, and discloses it directly to the organization. In return, they're usually recognized and, on many programs, paid — with the reward scaled to how serious the issue is.

Put plainly: I get paid to break things safely, then tell people exactly how I did it so they can fix it.
§03

Experience log

1999 – 2004

IT & Network Support Foundations

Started in hands-on IT support and early network administration — hardware, cabling, Windows/Unix systems, and the fundamentals that everything later was built on.

2004 – 2012

Network & Systems Engineering

Designed, managed, and secured enterprise network infrastructure and server environments — routing, firewalls, Active Directory, and large-scale systems administration.

2012 – 2020

Information Security & Penetration Testing

Moved into formal security roles — hardening infrastructure and running assessments, which is where the shift toward independent research really started.

2020 – Present

Independent Bug Bounty Researcher

Working independently now, across public and private programs, reporting straight to the organizations affected.

§04

Skill scope

AreaLevelDetails
Network Infrastructure & ProtocolsExpertRouting, switching, firewalls, VPNs, network segmentation and traffic analysis.
Systems AdministrationExpertLinux, Windows Server, and Unix environments — hardening, patching, and configuration review.
Web Application SecurityAdvancedAuthentication flaws, injection classes, access control, business logic issues.
Cloud SecurityAdvancedMisconfigurations and access issues across AWS, Azure, and GCP environments.
API & Mobile SecurityAdvancedREST/GraphQL testing, token handling, mobile app data exposure.
OSINT & ReconnaissanceExpertAttack surface mapping and asset discovery ahead of any active testing.
Scripting & AutomationProficientPython and Bash tooling to speed up recon, testing, and reporting.
Responsible Disclosure & ReportingExpertClear, reproducible write-ups that respect program scope and rules of engagement.
§05

Where I work

HackerOne
Active on this platform, engaging with public and private programs.
Bugcrowd
Active on this platform, engaging with public and private programs.
Intigriti
Active on this platform, engaging with public and private programs.
YesWeHack
Active on this platform, engaging with public and private programs.