Penetration Tester

Orange Tsai Portfolio

Security researcher whose multi-part public research on Microsoft Exchange (ProxyLogon, ProxyOracle, ProxyShell, ProxyRelay) and PHP/web server vulnerabilities is published in full technical detail, with an active archive spanning from 2019 to the present.

Web Security ResearchVulnerability ResearchExchange ServerPHP Security

What makes it work

A breakdown of the choices that make this portfolio stand out.

1

Named, real-world CVE-producing research

Publishing the actual research chain behind named vulnerability classes (ProxyLogon and related Exchange bugs) is a far stronger credential than describing "vulnerability research experience" generically — the work is independently verifiable via the CVEs it produced.

2

Bilingual publication (English and Traditional Chinese)

Publishing key research in two languages extends the audience deliberately rather than defaulting to English-only, widening the researcher's actual reach and influence.

3

Multi-year sustained research cadence

An archive running from 2019 to the present shows sustained output on hard problems rather than a single high-profile finding followed by silence.

What Penetration Testers can take from this

Specific, actionable tips to apply to your own portfolio — no generic advice.

  • If your research produced a named vulnerability or CVE, link the disclosure and technical writeup directly — it's independently verifiable in a way a resume bullet isn't.

  • Consider publishing significant research in more than one language if your work has an international audience — it meaningfully extends reach.

  • A multi-year archive of sustained research output is more convincing than one standout finding with nothing before or after it.

Ready to build your portfolio?

Follow the Penetration Tester roadmap — skills, projects, and timeline to get hired.

Penetration Tester Roadmap