Application & Platform Security · Toronto

I've spent four years on the researcher side of bug bounty programs.

I'd like to build one from the inside. I run security reviews, threat modeling, and vulnerability management, and I ship the fix in the codebase rather than filing the ticket. I also lead Canada's largest hacker community.

120+
Validated vulnerabilities
6+
Years in security
20+
Enterprise clients tested
4
Conference talks
What I Do

I run security reviews, architecture review, and threat modeling of design documents before code ships. I triage inbound disclosure reports, reproduce them, work out real impact, and track remediation to a fix that holds.

I've reported 120+ validated vulnerabilities through HackerOne, including severe issues on PayPal, plus Airbnb, Sony, Booking.com, and AT&T. Having been the researcher submitting to programs, I know which ones treat people well and which ones burn them.

Before consulting, I was the entire security function at a retail chain scaling toward national coverage. There was no security program, so I built one, and eventually put security checks inside the CI/CD pipelines. That was before DevSecOps was a common job title, and it's where I learned to automate first.

How I Work
01

Model the design, not just the build

A trust boundary drawn wrong on a whiteboard costs an afternoon. The same mistake in production costs a quarter. I model abuse cases with the engineers who wrote the doc.

02

Tune the tooling, don't just install it

A scanner at default settings buries a team in noise until they stop reading it, which is worse than nothing. I'd rather ship five findings a week that are all real than five hundred that aren't.

03

One bug, or a bug class

Findings get traced to root cause, then checked for the same pattern everywhere else. One IDOR is a bug. The same authorization mistake in nine places is a design problem.

Where I've Worked
White Tuque, Offensive Security Specialist
Toronto · Oct 2024 to Present
Security reviews, secure code review, threat modeling, and penetration testing across web, API, mobile, and cloud for 20+ enterprise clients, weighted toward banking and fintech. Own the vulnerability management loop end to end. Build security automation in Python, Go, and TypeScript. Mentor junior engineers on code review and report writing.
ASEC, Penetration Tester
Toronto · May 2024 to Oct 2024
Application security assessments for fintech and financial services clients across Canada, the US, Australia, and Europe, under Nick Aleks, former Senior Director of Security at Wealthsimple and now Head of Security at Robinhood. 150+ vulnerabilities across web, REST and GraphQL APIs, and cloud infrastructure.
DEF CON Toronto (DC416), Lead Organizer
Toronto · 2024 to Present
Lead Canada's largest hacker community: monthly meetups, speaker programming, sponsorships, and putting local researchers in front of a real audience. Also on the organizing committee for TASK, Toronto's longest-running security community.
HackerOne, Security Researcher
Remote · Feb 2022 to Present
120+ validated vulnerabilities across Fortune 500 disclosure programs. Focus on authentication and authorization bypass, privilege escalation, and multi-step business logic chains across web and API surfaces.
Projects & Research

Eidolon

Open source (MIT) AI-driven security workspace orchestrator that runs offensive workflows with an agent in the loop. Building it is how I learned where these systems break: tool-permission boundaries, agents doing confidently wrong things, and the gap between what a model says it did and what it did.  github.com/amir-hosseinpour/eidolon →

Ecovacs Deebot teardown

Hardware and firmware security research under the vendor's bug bounty program. UART console access, firmware extraction, then up through the cloud API and mobile app.

Offensive tooling

Burp Suite extension for automated OAuth2.0 and OIDC authorization-bypass detection, and a Nuclei template library for API and application vulnerability discovery.

Get in touch

Happy to talk whenever works for you.

amir.m.hosseinpour@gmail.com HackerOne profile