Babakizo · BlessedOps

When You Get Home

Your action center for tonight. Open one link, work down the list. Everything is paste-ready. Built while you were at work.

Tonight, in order

Highest leverage first. The whole run is about 45 focused minutes.

1 · LinkedIn

Re-rank the story: Security Researcher with CVEs first, founder as proof. This is the recruiter surface.
Headlinetap to select
Security Researcher (3 published CVEs) | AppSec & AI/MCP Security | Open to remote roles
Abouttap to select
I find the bugs that patches leave behind. I have published CVEs in software that thousands of teams run every day, including a coordinated advisory with IBM. My edge is variant and incomplete-fix analysis: I read the fix, then the fork history and the sibling code paths, and I find the residual gap the original patch missed. That is how I landed CVE-2026-55667 in File Browser (HIGH, CVSS 8.2), an access-control bypass in OpenBao that was patched upstream but still live in the fork, and a token-scope bypass in Gitea. I work at the frontier of MCP and AI-agent security: the SSRF, credential-forwarding, and auth-boundary flaws surfacing as teams race to ship AI tools. I am also an Immunefi-cleared smart-contract auditor with findings on dYdX and Polymarket. Alongside the research I build. I ship production websites with security baked in, and I built an autonomous multi-agent pipeline that continuously discovers and verifies vulnerability candidates. I am based in Calgary and open to remote security roles: application security, security research, product security, and AI security. If you want someone who breaks the system, understands the code, and ships the fix, let us talk.
Open to Work · set these

Turn on Open to Work and set job preferences (this is what makes recruiters find you):

Application Security EngineerSecurity ResearcherProduct Security EngineerAI / ML Security Location: Remote+ CanadaStart: Immediately
Skills to add
Vulnerability ResearchApplication SecurityMCP / AI-Agent SecurityIncomplete-fix & Variant AnalysisSSRFSource-Code ReviewPythonSmart-Contract AuditingBug Bounty
Featured · add these links

CVE-2026-55667 · File Browser (HIGH 8.2)
github.com/babakizo420/security-research (your tools + write-ups)
babakizo.com (your portfolio)

2 · Resume summary (in your voice)

This fixes the AI feel. Paste over your old summary, keep the rest, export a new PDF.
Summarytap to select
I find the bugs that patches leave behind. Three published CVEs in widely-used software, including a HIGH-severity flaw in File Browser (CVSS 8.2) and a cross-fork access-control bypass in OpenBao, plus a coordinated advisory with IBM. I specialize in incomplete-fix and variant analysis and in MCP and AI-agent security, and I am an Immunefi-cleared smart-contract auditor. I break the system, understand the code, and ship the fix.

3 · Your job list

Ready. Buddy compiled 30+ real openings in your lane, confidence-tiered (CONFIRMED-LIVE vs open-yourself), no invented links, with the receipt to lead with for each.

Open your full job list →

Top 5 to hit first
Built by your coordinator while you worked. Nothing here auto-sends. Every submit is your button.
Give first. Own the engine. Prove it, then repeat it.