Corben Leo Portfolio
Bug bounty hunter since 2016 against targets including the DoD, PayPal, Facebook, Google, Microsoft and Apple, publishing 22+ detailed vulnerability writeups (including a disclosed $1,000,000 KuCoin-related bounty) and co-founder of Boring Mattress Co.
What makes it work
A breakdown of the choices that make this portfolio stand out.
Writeups naming the exact vulnerability class and target
Each post specifies the exact bug type (SQL injection, SSRF, CORS misconfiguration, RCE) against a named target rather than a vague "found a critical vulnerability" summary — precise enough that other researchers can learn the technique.
A long, consistent bounty-hunting timeline
Dating the practice back to 2016 against a wide range of named organizations demonstrates sustained activity rather than a single lucky find.
Business ventures listed alongside security work
Naming a separate company he co-founded (Boring Mattress Co.) rounds out the profile as someone who ships things beyond security research, which differentiates it among bug bounty portfolios.
What Penetration Testers can take from this
Specific, actionable tips to apply to your own portfolio — no generic advice.
Name the exact vulnerability class in each writeup title and summary (SSRF, CORS, RCE) — specificity is what makes a bug bounty portfolio a learning resource, not just a highlight reel.
Show a multi-year timeline of findings against varied, named targets rather than presenting only your single biggest payout.
If you've built things outside of security work, it's fine to mention — it broadens how people perceive your capabilities.
More Penetration Tester portfolios
Ready to build your portfolio?
Follow the Penetration Tester roadmap — skills, projects, and timeline to get hired.