Penetration Tester

EdOverflow Portfolio

Team Lead and Senior Pentester at Cure53, and author of the security.txt standard (RFC 9116), with a public archive of bug bounty methodology writeups covering reconnaissance and CI/CD-focused research.

Bug BountySecurity StandardsReconnaissancePentesting Methodology

What makes it work

A breakdown of the choices that make this portfolio stand out.

1

Authorship of an actual internet standard

Writing security.txt into a formal IETF RFC (9116) is a concrete, permanent, independently checkable contribution — a different tier of credibility than a blog post claiming expertise.

2

A named senior title at a recognized firm alongside independent research

Listing a specific role (Team Lead & Senior Pentester at Cure53) grounds the more exploratory bug bounty writing in an established, professional day job.

3

Methodology writeups, not just result announcements

"Learn to build it, then break it" and similar posts focus on how to find issues, not just which bug was found — more durable, teachable content than a one-off disclosure story.

What Penetration Testers can take from this

Specific, actionable tips to apply to your own portfolio — no generic advice.

  • If you've contributed to a real standard, spec, or widely-adopted convention, lead with that — it's a permanent, checkable credential.

  • Pair a concrete job title at a named company with your independent research; the two together are more credible than either alone.

  • Write about methodology and process, not just results — 'how I find these' ages better and teaches more than a single bug story.

Ready to build your portfolio?

Follow the Penetration Tester roadmap — skills, projects, and timeline to get hired.

Penetration Tester Roadmap