Penetration Tester

Corben Leo Portfolio

Bug bounty hunter since 2016 against targets including the DoD, PayPal, Facebook, Google, Microsoft and Apple, publishing 22+ detailed vulnerability writeups (including a disclosed $1,000,000 KuCoin-related bounty) and co-founder of Boring Mattress Co.

Bug BountyVulnerability DisclosureWeb ExploitationSSRF

What makes it work

A breakdown of the choices that make this portfolio stand out.

1

Writeups naming the exact vulnerability class and target

Each post specifies the exact bug type (SQL injection, SSRF, CORS misconfiguration, RCE) against a named target rather than a vague "found a critical vulnerability" summary — precise enough that other researchers can learn the technique.

2

A long, consistent bounty-hunting timeline

Dating the practice back to 2016 against a wide range of named organizations demonstrates sustained activity rather than a single lucky find.

3

Business ventures listed alongside security work

Naming a separate company he co-founded (Boring Mattress Co.) rounds out the profile as someone who ships things beyond security research, which differentiates it among bug bounty portfolios.

What Penetration Testers can take from this

Specific, actionable tips to apply to your own portfolio — no generic advice.

  • Name the exact vulnerability class in each writeup title and summary (SSRF, CORS, RCE) — specificity is what makes a bug bounty portfolio a learning resource, not just a highlight reel.

  • Show a multi-year timeline of findings against varied, named targets rather than presenting only your single biggest payout.

  • If you've built things outside of security work, it's fine to mention — it broadens how people perceive your capabilities.

Ready to build your portfolio?

Follow the Penetration Tester roadmap — skills, projects, and timeline to get hired.

Penetration Tester Roadmap