Orange Tsai Portfolio
Security researcher whose multi-part public research on Microsoft Exchange (ProxyLogon, ProxyOracle, ProxyShell, ProxyRelay) and PHP/web server vulnerabilities is published in full technical detail, with an active archive spanning from 2019 to the present.
What makes it work
A breakdown of the choices that make this portfolio stand out.
Named, real-world CVE-producing research
Publishing the actual research chain behind named vulnerability classes (ProxyLogon and related Exchange bugs) is a far stronger credential than describing "vulnerability research experience" generically — the work is independently verifiable via the CVEs it produced.
Bilingual publication (English and Traditional Chinese)
Publishing key research in two languages extends the audience deliberately rather than defaulting to English-only, widening the researcher's actual reach and influence.
Multi-year sustained research cadence
An archive running from 2019 to the present shows sustained output on hard problems rather than a single high-profile finding followed by silence.
What Penetration Testers can take from this
Specific, actionable tips to apply to your own portfolio — no generic advice.
If your research produced a named vulnerability or CVE, link the disclosure and technical writeup directly — it's independently verifiable in a way a resume bullet isn't.
Consider publishing significant research in more than one language if your work has an international audience — it meaningfully extends reach.
A multi-year archive of sustained research output is more convincing than one standout finding with nothing before or after it.
More Penetration Tester portfolios
Ready to build your portfolio?
Follow the Penetration Tester roadmap — skills, projects, and timeline to get hired.