Penetration Tester

Sam Curry Portfolio

Security researcher known for automotive vulnerability research (remote vehicle control via license plate lookups in Kia and Subaru systems) and infrastructure-scale findings such as a modem vulnerability affecting millions of devices, published as long-form technical writeups.

Automotive SecurityAPI SecurityVulnerability ResearchIDOR

What makes it work

A breakdown of the choices that make this portfolio stand out.

1

Research spanning multiple, unrelated industries

Covering automotive systems, ISP infrastructure, and loyalty/rewards platforms in the same archive shows the underlying skill (finding broken authorization and API logic) transfers across very different targets, not just one niche.

2

Long-form writeups with stated read times

Publishing detailed, dated posts (7–21 minute reads) with a clear discovery-to-disclosure narrative gives readers the full technical chain, not just the headline finding.

3

Direct engagement channel (Discord) alongside the blog

Running a community Discord tied to the blog turns one-way publishing into an ongoing conversation with other researchers, extending the portfolio's reach beyond static posts.

What Penetration Testers can take from this

Specific, actionable tips to apply to your own portfolio — no generic advice.

  • If your research spans multiple industries or target types, say so explicitly — it demonstrates a transferable skill, not a one-trick specialty.

  • Include a realistic read-time or scope indicator on long writeups so readers can judge the depth before committing to read.

  • Pairing a blog with a live community channel (Discord, Slack) turns a static portfolio into an ongoing professional presence.

Ready to build your portfolio?

Follow the Penetration Tester roadmap — skills, projects, and timeline to get hired.

Penetration Tester Roadmap