Amir Hosseinpour

Application & Platform Security

I've spent four years on the researcher side of bug bounty programs. I'd like to build one from the inside.

The short version

Security engineer, six years in. 120+ validated vulnerabilities through HackerOne, including severe issues on PayPal. I know which disclosure programs treat researchers well and which ones burn them, because I've submitted to both kinds.

Day to day I run security reviews, threat modeling, and vulnerability management for enterprise clients, and I ship the fix in the codebase rather than filing the ticket. Before that I was the entire security function at a retail chain scaling toward national coverage, putting security checks into CI/CD pipelines before DevSecOps was a common job title.

I care more about tuning security tooling than installing it. A scanner at default settings buries a team in noise until they stop reading it, which is worse than nothing.

What I actually do

Review

Secure code review, architecture, threat modeling

Design documents get modeled before code exists. Findings get traced to root cause, then checked for the same pattern everywhere else in the codebase. One IDOR is a bug. The same authorization mistake in nine places is a design problem.

Disclose

Vulnerability management and disclosure programs

Intake, triage, reproduction, honest impact assessment, remediation tracked to a fix that holds. I've worked both ends of this loop, as the researcher filing and the consultant receiving.

Build

Security automation and tooling

Python, TypeScript, Go. Burp extensions, a Nuclei template library, and CI/CD security checks. I automate before I do anything a hundred times by hand.

Agents

Where AI systems break

Tool-permission boundaries, agents doing confidently wrong things, and the gap between what a model says it did and what it did. An agent with read access to production data and a write path into code is a genuinely new shape of problem.

Open source

Eidolon

An AI-driven security workspace orchestrator that runs offensive workflows with an agent in the loop. MIT licensed. Building it is how I learned where these systems fall over.

github.com/amir-hosseinpour/eidolon →

Talks

Explaining an attack to a room is a different skill from writing it up. This job needs both.

Speaking at SecTor 2025
SecTor 2025When Hackers Meet Burglars: Red Teaming the Smart Building
Speaking at DEF CON Vancouver
DEF CON VancouverAPI attack chains and OAuth2.0 exploitation. Microsoft-hosted.
Speaking at InfoSec Hamilton
InfoSec HamiltonOffensive security, in front of a regional crowd
Speaking at TASK
TASK 2025Toronto's longest-running security community

Community

I lead DEF CON Toronto (DC416), Canada's largest hacker community, and sit on the organizing committee for TASK. That part isn't incidental to security work. Running a disclosure program well is partly a reputation problem, and the researchers who report bugs are the people I put on stage every month.

DEF CON Toronto community event
DC416, one of the monthly sessions.

Get in touch

Happy to talk whenever works for you.

Email me Download résumé (PDF)