Red team and incident response in one job. I run adversarial simulations, then build the detection, playbooks, deception, and tabletop exercises that catch them. I've been incident commander on live incidents, and I lead Canada's largest hacker community.
I work both sides of the line. I run adversarial simulations and red team engagements end to end, from scope and rules of engagement through to findings, and I care less about the report than about whether the finding turns into detection that actually fires the next time.
On the defensive side I've served as incident commander on live incidents, built detection and response and a full incident response playbook set from scratch, and designed deception into a client's security architecture, honeypots, decoy credentials, and canary tokens wired to real alerts. I've also managed a team of engineers building our own in-house tabletop platform to run breach scenarios instead of just talking about them.
I've reported 120+ validated vulnerabilities through HackerOne, including severe issues on PayPal, and earlier I was the entire security function at a retail chain scaling toward national coverage, where I built the first security program from nothing. I lead DEF CON Toronto (DC416) and speak at SecTor and DEF CON Vancouver.
A trust boundary drawn wrong on a whiteboard costs an afternoon. The same mistake in production costs a quarter. I model abuse cases with the engineers who wrote the doc.
A scanner at default settings buries a team in noise until they stop reading it, which is worse than nothing. I'd rather ship five findings a week that are all real than five hundred that aren't.
Findings get traced to root cause, then checked for the same pattern everywhere else. One IDOR is a bug. The same authorization mistake in nine places is a design problem.
Open source (MIT) security workspace orchestrator I build and maintain in Python. Per-engagement isolation, scope tokens, a hash-chained audit log, and three-tier command gating. github.com/amir-hosseinpour/eidolon →
Hardware and firmware security research under the vendor's bug bounty program. UART console access, firmware extraction, then up through the cloud API and mobile app.
Burp Suite extension for automated OAuth2.0 and OIDC authorization-bypass detection, and a Nuclei template library for API and application vulnerability discovery.
Happy to talk whenever works for you.