Online Since 1996  /  Independent Security Research  /  Vulnerability Disclosure
REF// IR-2026-0824
SubjectShawn
ClassificationPublic Profile
Status● Active — Accepting Engagements
LocationCanada
Independent Bug Bounty Researcher

Shawn

I find security flaws before attackers do — and report them responsibly. 25+ years across networking, systems administration, and information security back every engagement.

$
§01

Summary

Started as a BBS SysOp in 1996. More than 25 years later, that same curiosity has grown through enterprise systems, networking, infrastructure, cloud, and now independent security research.

I'm an independent security researcher. I find, verify, and responsibly disclose vulnerabilities in web applications, networks, and cloud infrastructure. Before bug bounty, I spent two and a half decades in IT — networking, systems administration, and security — so I'm not just testing apps, I understand the infrastructure they run on.

Most of my work is under NDA, so I can't share client names or specific findings — details withheld — but I hold every report to the same bar: reproducible, clearly written, real impact.

25+
Years across IT, networking & security
4
Major Research Platforms
§02

What is bug bounty research?

Definition

A bug bounty is a program run by a company or organization that invites independent researchers to legally search for security weaknesses in their systems — websites, apps, APIs, and infrastructure — and report them privately, before criminals find them first.

Instead of exploiting a flaw, a researcher documents it, proves it's real with a safe proof-of-concept, and discloses it directly to the organization. In return, they're usually recognized and, on many programs, paid — with the reward scaled to how serious the issue is.

Put plainly: I get paid to break things safely, then tell people exactly how I did it so they can fix it.
§03

Background

1996

BBS SysOp

Ran a dial-up BBS — first hands-on exposure to systems, networks, and the communities built around them, long before any of it was a career.

2000s

Systems & Network Infrastructure

That BBS curiosity turned into professional IT work — network administration, systems engineering, and hands-on infrastructure.

2010s

Enterprise Infrastructure / Virtualization / Cloud

Moved into enterprise-scale systems — virtualization, large infrastructure environments, and the shift toward the cloud.

2020s

Independent Security Research & Vulnerability Disclosure

Now working independently across public and private bug bounty programs, reporting straight to the organizations affected.

§04

Research Focus

Web Application Security
Authentication & Access Control
API Security
OSINT & Attack-Surface Discovery
Network / Infrastructure Security
Cloud Environments
Responsible Vulnerability Disclosure
§05

Skill scope

AreaContext
Network Infrastructure25+ years
Web Application SecurityActive Research
OSINT & ReconnaissanceAttack Surface Discovery
API SecurityTesting & Research
Cloud SecurityAWS / Azure / GCP
ScriptingPython / Bash
Responsible DisclosureVulnerability Reporting
§06

How I Research

I focus on reproducible findings, real-world impact, minimal-risk testing, clear documentation, and responsible disclosure.

§07

Selected Research / Disclosures

entry pending
Sanitized write-up to be added once disclosure is complete.
entry pending
Sanitized write-up to be added once disclosure is complete.
§08

Research Platforms

HackerOne
Active on this platform, engaging with public and private programs.
Bugcrowd
Active on this platform, engaging with public and private programs.
Intigriti
Active on this platform, engaging with public and private programs.
YesWeHack
Active on this platform, engaging with public and private programs.