I find security flaws before attackers do — and report them responsibly. 25+ years across networking, systems administration, and information security back every engagement.
Started as a BBS SysOp in 1996. More than 25 years later, that same curiosity has grown through enterprise systems, networking, infrastructure, cloud, and now independent security research.
I'm an independent security researcher. I find, verify, and responsibly disclose vulnerabilities in web applications, networks, and cloud infrastructure. Before bug bounty, I spent two and a half decades in IT — networking, systems administration, and security — so I'm not just testing apps, I understand the infrastructure they run on.
Most of my work is under NDA, so I can't share client names or specific findings — details withheld — but I hold every report to the same bar: reproducible, clearly written, real impact.
A bug bounty is a program run by a company or organization that invites independent researchers to legally search for security weaknesses in their systems — websites, apps, APIs, and infrastructure — and report them privately, before criminals find them first.
Instead of exploiting a flaw, a researcher documents it, proves it's real with a safe proof-of-concept, and discloses it directly to the organization. In return, they're usually recognized and, on many programs, paid — with the reward scaled to how serious the issue is.
Ran a dial-up BBS — first hands-on exposure to systems, networks, and the communities built around them, long before any of it was a career.
That BBS curiosity turned into professional IT work — network administration, systems engineering, and hands-on infrastructure.
Moved into enterprise-scale systems — virtualization, large infrastructure environments, and the shift toward the cloud.
Now working independently across public and private bug bounty programs, reporting straight to the organizations affected.
| Area | Context |
|---|---|
| Network Infrastructure | 25+ years |
| Web Application Security | Active Research |
| OSINT & Reconnaissance | Attack Surface Discovery |
| API Security | Testing & Research |
| Cloud Security | AWS / Azure / GCP |
| Scripting | Python / Bash |
| Responsible Disclosure | Vulnerability Reporting |
I focus on reproducible findings, real-world impact, minimal-risk testing, clear documentation, and responsible disclosure.