Whoami
I'm a security researcher and penetration tester based in the Philippines, currently working as Principal Offensive Security Engineer at VikingCloud, where I lead a team of offensive security professionals.
I started out as a programmer, spending five years writing software before pivoting into information security — a move I've never looked back on. Today I focus on web application security, API testing, network penetration testing, and mobile security for clients worldwide.
Outside of my day job I've been hunting bugs on HackerOne and Bugcrowd since the early days, reporting over 1,000 valid vulnerabilities to more than 180 organizations, and racking up acknowledgements from Facebook, Microsoft, PayPal, Quora, SAP, HackerOne, and the U.S. Department of Defense. In 2016 I was ranked 5th globally among the most-voted hackers on HackerOne for the entire year.
I serve as a HackerOne Brand Ambassador for the Philippines, helping grow and support the local security research community.
Gamer by day. A bug bounty hunter by night.
Work History
Leads a team of offensive security engineers responsible for scoping, executing, and delivering high-stakes penetration tests for enterprise clients globally.
Delivered web application, API, network, mobile, and network segmentation testing engagements. Also covered dark web analysis and threat intelligence for global customers.
Conducted in-depth security assessments across web, network, and mobile targets for a diverse client portfolio.
Built software applications before transitioning fully into information security — a background that still informs how I approach source code review and logic-based vulnerabilities.
Credentials
B.S. Computer Science (Application Development) — University of Makati
Notable Findings
Also acknowledged by Facebook, Microsoft, PayPal, Quora, SAP, and the U.S. Department of Defense.
Publications
Community