Highlights
Hi 👋
I am aweb designer,developer,security researcher, and haveexperience triaging for numerous vulnerability disclosure programmes.
In 2016, I joinedGratipay’s Blue Team where Ioperated their bug bounty programme. Subsequently, in 2018, I joinedHackerOne as a Security Analyst. While atHackerOne, I had the privilege of triaging in-person alongside organisationssuch as GitHub, Salesforce, and the United States Marine Corps.
Currently, I am a Senior Pentester atCure53, where I usemy expertise to help clients strengthen their security posture by conductingsecurity audits and source code reviews.
Outside of work, I enjoy staying active and maintaining a strong dedication toswimming, honed during my time as a studenton theUniversity of Warwick’sSportsScholarshipprogramme.
PinnedLoading
- securitytxt/security-txt
securitytxt/security-txt PublicA proposed standard that allows websites to define security policies.
- can-i-take-over-xyz
can-i-take-over-xyz Public"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
- contact.sh
contact.sh PublicAn OSINT tool to find contacts in order to report security vulnerabilities.
- legal-bug-bounty
legal-bug-bounty Public#legalbugbounty project — creating safe harbors on bug bounty programs and vulnerability disclosure programs. Authored by Amit Elazari.
- securitytxt/securitytxt.org
securitytxt/securitytxt.org PublicStatic website for security.txt.
If the problem persists, check theGitHub status page orcontact support.
Uh oh!
There was an error while loading.Please reload this page.





