Application Security Engineer with 10+ years in offensive security and 3 years specialising in Web3. Approaches every target from the attacker's perspective, whether it's a web app, an API, a DApp, or a DeFi protocol. Equally comfortable finding the vulnerability, assessing its severity, and working with engineering to get it fixed. At Immunefi, single-handedly prevented the loss of $7.3M in client TVL through one finding and led triage on flagship audit competitions including Lido, Folks Finance and Plume Network. Brings a researcher's instinct for impact, an auditor's discipline for severity calibration, and the communication skills to land remediation work without friction. Recognised by Meta, Google, Apple, Microsoft, PayPal and the U.S. Department of Defense.
Immunefi
•Performed security reviews and code audits for external clients, including a finding that prevented the loss of a client's entire $7.3M TVL. •Reviewed and validated thousands of web application, smart contract, and blockchain vulnerability reports, assessing severity and exploitability against each client's threat model. •Led triage for audit competitions (Lido, Folks Finance, Plume Network, Shardeum), defining review standards, calibrating severity ratings, and managing high-volume submission workflows. •Provided security guidance and remediation recommendations to engineering teams, translating complex vulnerability findings into actionable fixes and bridging the gap between researchers and developers. •Mediated thousands of disputes between bounty programs and researchers; produced technical assessments both sides relied on to reach resolution. •Conducted internal penetration testing and architecture review of Immunefi's platform alongside the engineering team.
Synack
•Performed security assessments of enterprise web applications and APIs through controlled, time-boxed engagements on Synack's managed platform. •Reported 85 valid vulnerabilities ranging from Medium to Critical severity, including injection, authentication bypass, and access control flaws. •Combined source code review and black-box testing approaches depending on engagement scope and target stack. •Delivered vulnerability reports with remediation recommendations used by client engineering teams to prioritise and resolve findings.
Self-Employed
•Reported 200+ valid vulnerabilities across HackerOne, Bugcrowd, and Immunefi, spanning Broken Access Control, Business Logic, XSS, RCE, SSRF, SSTI, and server misconfiguration classes. •Reported bugs to Meta, Google, Microsoft, PayPal, Yahoo and multiple other organisations. •Produced detailed proof-of-concept reports for each finding and coordinated with program teams to validate remediation.
MSc
Distinction
Bachelor of Computing
First Class Honours
Diploma