Jason Haddix Portfolio
Offensive security leader with 15 years in the field, formerly in head-of-research and trust roles at Bugcrowd and HackerOne, publishing bug bounty reconnaissance methodology and training through his own site and talks.
What makes it work
A breakdown of the choices that make this portfolio stand out.
Career spanning both the practitioner and platform side of bug bounty
Having worked inside two major bug bounty platforms (Bugcrowd, HackerOne) as well as independently gives a rare dual perspective — how researchers work and how programs are run — that a pure practitioner's portfolio wouldn't show.
Explicit years-of-experience framing
Stating "15 years" directly on the homepage gives visitors an immediate, unambiguous sense of seniority rather than requiring them to infer it from a list of past roles.
Consulting and training offered alongside personal content
Positioning himself for training and consulting engagements, not just content consumption, signals the site is a professional practice hub, not only a personal blog.
What Penetration Testers can take from this
Specific, actionable tips to apply to your own portfolio — no generic advice.
If you've worked on both the practitioner and platform/program side of an industry, make that dual perspective explicit — it's a distinctive credential few others can claim.
State your years of experience plainly on the homepage rather than making visitors calculate it from a timeline.
If you're open to consulting or training work, say so directly on the homepage rather than only implying it through your content.
More Penetration Tester portfolios
Ready to build your portfolio?
Follow the Penetration Tester roadmap — skills, projects, and timeline to get hired.