Tonight, in order
Highest leverage first. The whole run is about 45 focused minutes.
- 1 LinkedIn overhaul (10 min): paste the headline, About, and skills below, then flip on Open to Work.
- 2 Pin your GitHub repos (2 min): profile → Customize your pins → security-research, security-dashboard, headerguard.
- 3 Apply (30 min): open Buddy's job list, hit the top 5 first, 3 to 5 today. Lead with File Browser 8.2 + the MCP angle.
- 4 Resume (5 min): drop the rewritten summary below into your doc, export a fresh PDF.
- 5 Reel: generate the 2 Omni scenes in the Gemini app (intro + CVE explainer), send me the clips, I reassemble with your VO.
- 6 Passport: send me the scan whenever, I watermark + lock it before it goes anywhere.
1 · LinkedIn
Re-rank the story: Security Researcher with CVEs first, founder as proof. This is the recruiter surface.
Headlinetap to select
Security Researcher (3 published CVEs) | AppSec & AI/MCP Security | Open to remote roles
Abouttap to select
I find the bugs that patches leave behind.
I have published CVEs in software that thousands of teams run every day, including a coordinated advisory with IBM. My edge is variant and incomplete-fix analysis: I read the fix, then the fork history and the sibling code paths, and I find the residual gap the original patch missed. That is how I landed CVE-2026-55667 in File Browser (HIGH, CVSS 8.2), an access-control bypass in OpenBao that was patched upstream but still live in the fork, and a token-scope bypass in Gitea.
I work at the frontier of MCP and AI-agent security: the SSRF, credential-forwarding, and auth-boundary flaws surfacing as teams race to ship AI tools. I am also an Immunefi-cleared smart-contract auditor with findings on dYdX and Polymarket.
Alongside the research I build. I ship production websites with security baked in, and I built an autonomous multi-agent pipeline that continuously discovers and verifies vulnerability candidates.
I am based in Calgary and open to remote security roles: application security, security research, product security, and AI security. If you want someone who breaks the system, understands the code, and ships the fix, let us talk.
Open to Work · set these
Turn on Open to Work and set job preferences (this is what makes recruiters find you):
Application Security EngineerSecurity ResearcherProduct Security EngineerAI / ML Security
Location: Remote+ CanadaStart: Immediately
Skills to add
Vulnerability ResearchApplication SecurityMCP / AI-Agent SecurityIncomplete-fix & Variant AnalysisSSRFSource-Code ReviewPythonSmart-Contract AuditingBug Bounty
2 · Resume summary (in your voice)
This fixes the AI feel. Paste over your old summary, keep the rest, export a new PDF.
Summarytap to select
I find the bugs that patches leave behind. Three published CVEs in widely-used software, including a HIGH-severity flaw in File Browser (CVSS 8.2) and a cross-fork access-control bypass in OpenBao, plus a coordinated advisory with IBM. I specialize in incomplete-fix and variant analysis and in MCP and AI-agent security, and I am an Immunefi-cleared smart-contract auditor. I break the system, understand the code, and ship the fix.
3 · Your job list
Ready. Buddy compiled 30+ real openings in your lane, confidence-tiered (CONFIRMED-LIVE vs open-yourself), no invented links, with the receipt to lead with for each.
Open your full job list →
Top 5 to hit first
- 1 Mozilla, Senior Product Security Engineer. Remote Canada, CAD 104-139k. Cleanest fit. Lead File Browser 8.2.
- 2 Runlayer, MTS Security. Remote US-tz. MCP/agent security, almost bespoke. Lead the MCP angle.
- 3 Canonical, Security Software Engineer. Worldwide remote, Go. Lead OpenBao + Gitea.
- 4 Chainguard, Senior Product Security Engineer. Remote US, $157-184k. Lead variant analysis.
- 5 Anthropic, Staff+ AppSec. Remote-friendly, $320-485k. Their JD literally describes your autonomous pipeline. A stretch on seniority, but apply strong.