Available for selected engagements

INDEPENDENT SECURITY TESTING · BUG BOUNTY

I find vulnerabilities.I help close them.

I help product teams uncover meaningful weaknesses in web applications and APIs — with reproducible evidence, clear risk context and an actionable path to remediation.

Authorized testing only · NDA available · English

STATUS / NOW

Research mode: active

scopeconfirmed
surfacemapped
evidencereproducible
reportactionable
01

Clear scope and authorization

02

Responsible disclosure

03

Developer-ready reporting

ENGAGEMENTS

Security work that ends with a decision — not a scanner dump.

The scope follows your product stage, critical user journeys and actual threat model.

/01

Web application testing

Manual assessment of authentication, authorization, sessions, input handling and business logic, focused on the paths with the greatest impact.

OWASPAuthenticationBusiness logic
/02

API security testing

REST and GraphQL review for BOLA/IDOR, excessive data exposure, access control, rate limits and process abuse.

RESTGraphQLAccess control
/03

Bug bounty & report validation

Vulnerability validation, false-positive reduction, impact reproduction and support with a safe, accurate response.

TriagePoCDisclosure

THE PROCESS

From scope to remediation, without a black box.

  1. 01

    Scope

    We agree on goals, critical flows, environments, test accounts, constraints and a secure communication channel.

  2. 02

    Research

    I map the attack surface and manually validate scenarios, documenting only reproducible results.

  3. 03

    Report

    You receive a clear description, reproduction steps, impact, evidence and practical remediation guidance.

  4. 04

    Retest

    After remediation, I verify closure and regression risk, with a clear outcome for business and engineering.

ANATOMY OF A STRONG REPORT

Issue. Impact. Evidence. Fix.

Each card is the anatomy of a finding — issue, impact, evidence, fix. Representative of the work I do, not a specific client engagement.

ACCESS CONTROL

Accessing another user's resource by changing an identifier

Impact
Potential unauthorized reading or modification of customer data.
Evidence
A minimal two-role reproduction and the exact HTTP request needed to demonstrate the issue.
Remediation
Server-side object authorization plus regression tests across every resource operation.
AUTHENTICATION

Bypassing a restriction in an account-recovery flow

Impact
Potential account takeover in a specific edge-case scenario.
Evidence
A documented chain of conditions without exposing live secrets or customer data.
Remediation
Bind the token to the account and action, add expiry and invalidate it after use.
API / DATA EXPOSURE

Excessive field exposure in an API response

Impact
Disclosure of data not required by the interface and unavailable in the UI.
Evidence
A contract-versus-response comparison using the least-privileged role.
Remediation
An explicit DTO allowlist and a contract test that prevents regression.
Jakub Kozub — Security Researcher
Jakub Kozub · Security Researcher

ABOUT

A researcher's curiosity. A partner's communication.

I focus on testing web applications and APIs, with particular attention to access control, authentication and business logic — with ongoing authorization research across WordPress, Elastic, GitLab and Matomo.

By day I work as a SOC L2 analyst at Jagiellonian University — a blue-team background that shapes how I test: I read source code, run every proof of concept in a local lab before filing, and report only what I actually measured.

Every engagement is grounded in explicit authorization, minimal operational impact and responsible disclosure. A good report should help fix the problem — not merely prove it exists.

FOCUS AREAS

  • OWASP Top 10
  • Web applications
  • REST / GraphQL API
  • Authentication & authorization
  • Business logic
  • Responsible disclosure

VERIFIABLE PROOF

  • Valid access-control finding in WordPress, reported via HackerOne — bounty awarded (2026); approved Wordfence researcher
  • Competitive CTF: 4× podium including two 1st places (SentinelOne ThreatOps, Recorded Future) and 3rd at Trend Micro’s European CTF
  • Public HackerOne profile with reputation, badges and hacktivity — linked in the footer
  • Certifications: eCTHP · CDSA · BTL1 · postgraduate offensive security (University of Warsaw)
  • SOC L2 background: detection, log analysis and threat hunting in daily practice
  • Open-source security tooling on GitHub: wp-authz-audit, evidence-redaction-gate, redact-request

FAQ

Before we start.

01Do you test without written authorization?

No. Every commercial engagement requires an agreed scope and explicit authorization. In bug bounty programs, I stay strictly within the published policy.

02Do you test production systems?

When the scope requires it, production testing is performed carefully under agreed rules of engagement. I prefer test accounts, agreed windows and low-impact techniques.

03What does the team receive?

A report with an executive summary and technical detail: reproduction steps, evidence, impact, priority and remediation recommendations.

04How is an engagement priced?

After a short conversation about scope, architecture, user roles and timing. A fixed price works for a well-defined scope; phased pricing is also possible.

HAVE A PRODUCT TO TEST?

Let's discuss the attack surface before it becomes a headline.

Tell me what the product is, what should be in scope and the timing you have in mind. I will reply with the questions needed for a reliable estimate.

I usually reply within 1–2 business days.

Poland · remote worldwide · English · Polish