Credentials
Everything on this page is checkable. Certifications carry the credential ID the issuer will confirm, advisories link to the CVE record, and Hall of Fame entries link to the published page.
Certifications
OffSec Certified Professional Plus (OSCP+)
OffSecCredential ID: OS-57216833
Verify with OffSec →CREST Registered Tester (CRT)
CRESTCredential ID: 7657380034
Verify with CREST →CREST Practitioner Security Analyst (CPSA)
CRESTCredential ID: 7657380034
Verify with CREST →Published advisories
Disclosure acknowledgements
Vulnerabilities reported and acknowledged across healthcare, fintech, AI infrastructure, B2B SaaS, education and civic technology.
Many were disclosed through private programmes, whose terms cover the existence of the programme and not only the finding. Those organisations are not named here. Details are available on request, subject to their permission. The public ones are:
Experience
Offensive Security Engineer, Penetration Tester, DeepStrike
December 2023 to presentFull-scope penetration testing across web applications, REST and GraphQL APIs, mobile, external networks and Active Directory. Internal assessments mapping attack paths from initial foothold to domain compromise.
Offensive Security Engineer, BugSwagger
April 2023 to October 2023Penetration testing of web applications, APIs and thick clients, including manual source code review of client-side binaries.
Independent vulnerability researcher, HackerOne
November 2022 to presentPublic bug bounty research. Access control, authentication and business logic flaws, leading to CVE-2026-44977 and the acknowledgements listed above.
Happy to walk through any of this in detail.