Penetration Tester

James Kettle Portfolio

Director of Research at PortSwigger (Burp Suite), credited with pioneering HTTP desync attacks and request smuggling techniques and building tools including Param Miner, Turbo Intruder, and the OAST technology behind Burp Collaborator.

HTTP Request SmugglingWeb Cache PoisoningBurp Suite ToolingVulnerability Research

What makes it work

A breakdown of the choices that make this portfolio stand out.

1

Attack techniques with lasting industry-wide impact

HTTP request smuggling and web cache poisoning, as he helped popularize them, are now standard categories in professional web app pentests — his portfolio is effectively a history of techniques that reshaped the field's methodology.

2

Tools built to scale his own research, then released publicly

Turbo Intruder and Param Miner were built to solve his own research problems (large-scale timing attacks, hidden parameter discovery) and then shipped as tools thousands of other testers now use.

3

An annual public research retrospective

The recurring "Top 10 Web Hacking Techniques" project gives the community a yearly, crowd-vetted summary of the field's most significant findings — sustained curatorial work on top of his own research.

What Penetration Testers can take from this

Specific, actionable tips to apply to your own portfolio — no generic advice.

  • If a technique or attack class you helped establish is now a standard part of how the field tests for it, state that plainly and let the industry adoption speak for itself.

  • Turn tools you build to solve your own research problems into public releases — other practitioners using your tooling is durable, ongoing proof of impact.

  • Running or contributing to a recurring, community-facing summary of the year's work (a 'best of' roundup) builds authority beyond your own individual findings.

Ready to build your portfolio?

Follow the Penetration Tester roadmap — skills, projects, and timeline to get hired.

Penetration Tester Roadmap