Credentials

Everything on this page is checkable. Certifications carry the credential ID the issuer will confirm, advisories link to the CVE record, and Hall of Fame entries link to the published page.

Certifications

OffSec Certified Professional Plus (OSCP+)

OffSec

Credential ID: OS-57216833

Verify with OffSec →

CREST Registered Tester (CRT)

CREST

Credential ID: 7657380034

Verify with CREST →

CREST Practitioner Security Analyst (CPSA)

CREST

Credential ID: 7657380034

Verify with CREST →

Published advisories

CVE-2026-44977

Stored cross-site scripting in a feedback file upload

Impact: Account takeover

Disclosure acknowledgements

Vulnerabilities reported and acknowledged across healthcare, fintech, AI infrastructure, B2B SaaS, education and civic technology.

Many were disclosed through private programmes, whose terms cover the existence of the programme and not only the finding. Those organisations are not named here. Details are available on request, subject to their permission. The public ones are:

K HealthGreenhouse

Security Hall of Fame: EMBL-EBI, Crunch

Experience

Offensive Security Engineer, Penetration Tester, DeepStrike

December 2023 to present

Full-scope penetration testing across web applications, REST and GraphQL APIs, mobile, external networks and Active Directory. Internal assessments mapping attack paths from initial foothold to domain compromise.

Offensive Security Engineer, BugSwagger

April 2023 to October 2023

Penetration testing of web applications, APIs and thick clients, including manual source code review of client-side binaries.

Independent vulnerability researcher, HackerOne

November 2022 to present

Public bug bounty research. Access control, authentication and business logic flaws, leading to CVE-2026-44977 and the acknowledgements listed above.

Happy to walk through any of this in detail.