Sam Curry Portfolio
Security researcher known for automotive vulnerability research (remote vehicle control via license plate lookups in Kia and Subaru systems) and infrastructure-scale findings such as a modem vulnerability affecting millions of devices, published as long-form technical writeups.
What makes it work
A breakdown of the choices that make this portfolio stand out.
Research spanning multiple, unrelated industries
Covering automotive systems, ISP infrastructure, and loyalty/rewards platforms in the same archive shows the underlying skill (finding broken authorization and API logic) transfers across very different targets, not just one niche.
Long-form writeups with stated read times
Publishing detailed, dated posts (7–21 minute reads) with a clear discovery-to-disclosure narrative gives readers the full technical chain, not just the headline finding.
Direct engagement channel (Discord) alongside the blog
Running a community Discord tied to the blog turns one-way publishing into an ongoing conversation with other researchers, extending the portfolio's reach beyond static posts.
What Penetration Testers can take from this
Specific, actionable tips to apply to your own portfolio — no generic advice.
If your research spans multiple industries or target types, say so explicitly — it demonstrates a transferable skill, not a one-trick specialty.
Include a realistic read-time or scope indicator on long writeups so readers can judge the depth before committing to read.
Pairing a blog with a live community channel (Discord, Slack) turns a static portfolio into an ongoing professional presence.
More Penetration Tester portfolios
Ready to build your portfolio?
Follow the Penetration Tester roadmap — skills, projects, and timeline to get hired.