i get asked to fill vulnerability research roles with highly qualified people. if you think you fit the bill let me know.

where i reach you. a throwaway is fine.
cve, advisory, writeup, talk, repo, blog, ctf profile. one link is enough. if you want a name or handle attached, put it on a line here.

what this is

this is a list of people in a file i keep. it is not a job board and it is not a product. when a company comes to me looking for someone who can actually find bugs, i read the list, think of two or three people, and email them.

i keep it short on purpose. the reason it is worth being on is that it is short.

what i ask for

i ask for two things

  • an email address. a throwaway is fine.
  • links to public work. cves, advisories, writeups, pwn2own, con talks, a github, a blog, a ctf handle. one link is enough.

i don't ask for

  • a resume or cv
  • your current employer
  • where you live
  • your real name
  • a phone number
  • anything about work you can't talk about

handles are fine. a real name is optional.

how a role reaches you

  1. a company describes a role to me. i ask what the work actually is and what it actually pays.
  2. i think of a few people on the list who fit it. i email them. the email names the company and names the role.
  3. if you say yes, i introduce you to that one company for that one role.

who pays

companies pay me. you never pay me.

what happens to your data

what i store
the email you give me, the links you give me, and sometimes a short note i write to myself so i remember you
how to be deleted
reply to any email from me with the word delete.
unsubscribe
reply stop to any email and you will not hear from me again.