I've spent four years on the researcher side of bug bounty programs. I'd like to build one from the inside.
Security engineer, six years in. 120+ validated vulnerabilities through HackerOne, including severe issues on PayPal. I know which disclosure programs treat researchers well and which ones burn them, because I've submitted to both kinds.
Day to day I run security reviews, threat modeling, and vulnerability management for enterprise clients, and I ship the fix in the codebase rather than filing the ticket. Before that I was the entire security function at a retail chain scaling toward national coverage, putting security checks into CI/CD pipelines before DevSecOps was a common job title.
I care more about tuning security tooling than installing it. A scanner at default settings buries a team in noise until they stop reading it, which is worse than nothing.
Design documents get modeled before code exists. Findings get traced to root cause, then checked for the same pattern everywhere else in the codebase. One IDOR is a bug. The same authorization mistake in nine places is a design problem.
Intake, triage, reproduction, honest impact assessment, remediation tracked to a fix that holds. I've worked both ends of this loop, as the researcher filing and the consultant receiving.
Python, TypeScript, Go. Burp extensions, a Nuclei template library, and CI/CD security checks. I automate before I do anything a hundred times by hand.
Tool-permission boundaries, agents doing confidently wrong things, and the gap between what a model says it did and what it did. An agent with read access to production data and a write path into code is a genuinely new shape of problem.
An AI-driven security workspace orchestrator that runs offensive workflows with an agent in the loop. MIT licensed. Building it is how I learned where these systems fall over.
github.com/amir-hosseinpour/eidolon →Explaining an attack to a room is a different skill from writing it up. This job needs both.
I lead DEF CON Toronto (DC416), Canada's largest hacker community, and sit on the organizing committee for TASK. That part isn't incidental to security work. Running a disclosure program well is partly a reputation problem, and the researchers who report bugs are the people I put on stage every month.
Happy to talk whenever works for you.
Email me Download résumé (PDF)