Helped secure 25+ organizations.
// responsible disclosureMore than 25 organizations have closed a security gap after a report from me. Google, Apple, Meta, Microsoft, McAfee, ESET, Harvard, Cambridge, Intel, Lenovo, BBC News and many more. Every finding went through the vendor’s own disclosure program, was triaged by their security team, and was fixed before it was made public. Documentation available on request.
Google Vulnerability Reward Program
Googleplex, Waze and Google internal assets. Triaged and accepted by the VRP panel, listed in the Hall of Fame, and $5,000+ paid out.
“Nice catch! I’ve filed a product bug for this issue. We’ll work with the product team to ensure this issue is addressed.”
Martin, Google Security Team · status: accepted| 2022 | Stored XSS and further issues across Googleplex, Waze and internal assets. More than $5,000 in bounties and a Hall of Fame listing. | |
| Meta | 2021 | Messenger vulnerability. A $750 bounty from the Facebook security team and a place in the whitehat Hall of Fame. |
| ESET | 2021 | Letter of thanks from the Chief Information Security Officer. |
| Apple | 2020 | Vulnerability on filemaker.com, an Apple-owned property. Listed in Apple’s web server security credits. |
| Microsoft | 2020 | Reflected XSS on a Microsoft acquisition. Listed in the MSRC acknowledgements. |
| BBC News | 2020 | Rate-limit bypass. Listed first on the 2020 security disclosure page. |
| Huawei | 2020 | Letter of acknowledgement from Huawei PSIRT. |
| Harvard University | 2019 | Letter of thanks from the Chief Information Security Officer. |
| Cambridge University | 2019 | Letter from the Cambridge CSIRT. |
| Intel | 2019 | Certificate of appreciation from the investigations team. |
| McAfee | 2019 | Certificate of acknowledgement signed by the Chief Information Security Officer. |
| Lenovo | 2018 | Letter of acknowledgement from Lenovo PSIRT. |
First place at the Pre-DEF CON CTF.
// competitionsI walked into HackerDojo for the Pacific Hackers Pre-DEF CON Capture the Flag, the Silicon Valley qualifier that draws the crowd heading to Las Vegas, and walked out in first place. That win put me in the room: invited and sponsored to DEF CON twice and to Black Hat USA once.
Offensive instincts, enterprise IT depth.
// experienceBug Bounty Hunter, Bugcrowd
2026 – present · remote- Perform reconnaissance, vulnerability assessment and exploitation against real-world web application and API targets in authorized programs.
- Write clear, actionable reports with reproduction steps and remediation guidance that engineering teams can act on.
Technical Support Analyst (Internship), NVIDIA
2026 · santa clara, ca- Reimaged endpoints across Windows, macOS and Linux, enforcing security baselines and MDM enrollment through Jamf Pro and Intune, with QA validation before every deployment.
- Served as the primary walk-in analyst at the Tech Lounge, resolving hardware and software faults, AI developer tooling issues, GlobalProtect VPN failures and Wi-Fi disruptions.
- Owned and resolved escalated remote tickets in ServiceNow and Jira, including passkey and MFA failures, across cloud, VDI and Fleet-managed endpoints.
Year Up United, IT Support Training
2025 · online- Completed the IT support training program before joining NVIDIA.
What I work with.
// toolkitoffensive security
Penetration testing, bug bounty research, vulnerability assessment, OWASP Top 10, CVE analysis, MITRE ATT&CK, Kali Linux, Burp Suite, responsible disclosure.
soc & threat defense
SIEM, alert triage, threat hunting, log analysis, IDS and IPS, Wireshark, incident response, malware analysis, phishing triage, EDR, zero trust.
enterprise it
Microsoft Entra ID, Active Directory, MFA and SSO, Jamf Pro, Intune, endpoint hardening, Fortinet, GlobalProtect VPN, Cisco, TCP/IP, VDI, Google Cloud.
tools
Python, Bash, Git, ServiceNow, Jira.
- OSCPin progressOffensive Security—
- Claude 101, AI FluencyAnthropic2026
- Google Cloud CybersecurityCoursera2025
- Fortinet Network SecurityFortinet2024
- Certified Ethical Hacker (CEH)EC-Council2019
Disclosures that made the news.
// coverage- Tech PanaStored XSS disclosed to Google and rewarded by the VRPtech media
- Tech PanaVulnerability disclosed in Waze, a Google acquisitiontech media
- Tech PanaVulnerability disclosed in Meta Messengertech media
- Capital NepalVulnerability disclosed in Facebook Messengerbusiness magazine
- The Annapurna ExpressInterview on ethical hacking and responsible disclosurenational daily
- GorkhapatraFeature on bug bounty hunting as a careernational newspaper
Ship it. Then let me try to break it.
Open to penetration testing, security analyst and SOC roles in the Bay Area or remote.