Skip to content

For hiring teams

I find vulnerabilities in systems that ship, and prove them with exploits

I'm an Associate Researcher on the ICS Security Research Team at CoreSecurity, glad to hear from teams working on hard security problems. This page is the shortest route through the evidence; timing and fit are discussed directly.

29public findings
24assigned CVEs
7research areas
5cyber exercises

Relevant mandates

  • OT/ICS security (IEC 62443) and industrial device assessment and certification testing
  • IoT and firmware vulnerability research, reverse engineering, and exploit development
  • Linux kernel and binary vulnerability research and fuzzing
  • Web/app penetration testing and LLM inference-engine security

Selected experience

2021.06 - Present

ICS Security Researcher (Associate Researcher) · CoreSecurity

OT/ICS security — performed IEC 62443-4-2 based threat modeling and penetration testing. Earned the Achilles Communication Certificate Level 2 for LS ELECTRIC automation devices and developed an automated assessment tool. IoT security — developed and validated smart-building IoT vulnerability-detection technology and built IoT/CCTV incident-investigation tools.

2020.06 - 2021.06

Web/App Pentester (Staff) · A3 Security

Performed penetration testing of financial and public electronic-finance infrastructure. Targets included Cham Savings Bank, Acuon Capital, KOFIA, SBI Savings Bank, Hyundai Motor (HKMC), and Nonghyup RPA. Performed security reviews of non-standard systems. Targets included the KT GiGA Genie AI speaker, IoT thermal-detection equipment, and DB Insurance's claim-call system.