EdOverflow Portfolio
Team Lead and Senior Pentester at Cure53, and author of the security.txt standard (RFC 9116), with a public archive of bug bounty methodology writeups covering reconnaissance and CI/CD-focused research.
What makes it work
A breakdown of the choices that make this portfolio stand out.
Authorship of an actual internet standard
Writing security.txt into a formal IETF RFC (9116) is a concrete, permanent, independently checkable contribution — a different tier of credibility than a blog post claiming expertise.
A named senior title at a recognized firm alongside independent research
Listing a specific role (Team Lead & Senior Pentester at Cure53) grounds the more exploratory bug bounty writing in an established, professional day job.
Methodology writeups, not just result announcements
"Learn to build it, then break it" and similar posts focus on how to find issues, not just which bug was found — more durable, teachable content than a one-off disclosure story.
What Penetration Testers can take from this
Specific, actionable tips to apply to your own portfolio — no generic advice.
If you've contributed to a real standard, spec, or widely-adopted convention, lead with that — it's a permanent, checkable credential.
Pair a concrete job title at a named company with your independent research; the two together are more credible than either alone.
Write about methodology and process, not just results — 'how I find these' ages better and teaches more than a single bug story.
More Penetration Tester portfolios
Ready to build your portfolio?
Follow the Penetration Tester roadmap — skills, projects, and timeline to get hired.