I find security flaws before attackers do — and report them responsibly. 25+ years across networking, systems administration, and information security back every engagement.
I'm an independent security researcher. I find, verify, and responsibly disclose vulnerabilities in web applications, networks, and cloud infrastructure. Before bug bounty, I spent two and a half decades in IT — networking, systems administration, and security — so I'm not just testing apps, I understand the infrastructure they run on.
Most of my work is under NDA, so I can't share client names or specific findings — details withheld — but I hold every report to the same bar: reproducible, clearly written, real impact.
A bug bounty is a program run by a company or organization that invites independent researchers to legally search for security weaknesses in their systems — websites, apps, APIs, and infrastructure — and report them privately, before criminals find them first.
Instead of exploiting a flaw, a researcher documents it, proves it's real with a safe proof-of-concept, and discloses it directly to the organization. In return, they're usually recognized and, on many programs, paid — with the reward scaled to how serious the issue is.
Started in hands-on IT support and early network administration — hardware, cabling, Windows/Unix systems, and the fundamentals that everything later was built on.
Designed, managed, and secured enterprise network infrastructure and server environments — routing, firewalls, Active Directory, and large-scale systems administration.
Moved into formal security roles — hardening infrastructure and running assessments, which is where the shift toward independent research really started.
Working independently now, across public and private programs, reporting straight to the organizations affected.
| Area | Level | Details |
|---|---|---|
| Network Infrastructure & Protocols | Expert | Routing, switching, firewalls, VPNs, network segmentation and traffic analysis. |
| Systems Administration | Expert | Linux, Windows Server, and Unix environments — hardening, patching, and configuration review. |
| Web Application Security | Advanced | Authentication flaws, injection classes, access control, business logic issues. |
| Cloud Security | Advanced | Misconfigurations and access issues across AWS, Azure, and GCP environments. |
| API & Mobile Security | Advanced | REST/GraphQL testing, token handling, mobile app data exposure. |
| OSINT & Reconnaissance | Expert | Attack surface mapping and asset discovery ahead of any active testing. |
| Scripting & Automation | Proficient | Python and Bash tooling to speed up recon, testing, and reporting. |
| Responsible Disclosure & Reporting | Expert | Clear, reproducible write-ups that respect program scope and rules of engagement. |