
Johnson M
Application Security Analyst
Habilidades

Revisa mis servicios

Porfolio
Experiencia laboral
cyber sucurity
Hackers Academy
Dec 2024 - Present • 1 yr 10 mos
Independent Security Researcher – Bug Bounty Hunter HackerOne — Public and Private Bug Bounty Programs August 2025 – Present | Remote Conduct authorized security testing of production web applications and APIs to identify vulnerabilities and business-logic flaws. Achieved a HackerOne Signal score of 7.00, placing in the 99th percentile, and an Impact score of 15.00. Ranked #3 in Kenya on HackerOne’s national leaderboard for Web Application and Broken Access Control submissions in Q3 2026. Discovered and responsibly reported broken access control vulnerabilities, API information disclosures, and incomplete security fixes that exposed restricted user and event-related information. Performed reconnaissance, endpoint mapping, manual testing, exploitation proof-of-concept development, vulnerability reproduction, and responsible disclosure reporting. Applied the OWASP Top 10 methodology to identify access-control gaps, API weaknesses, sensitive-data exposure, and other web application security issues. Selected to test invite-only private bug bounty programs based on the quality and reliability of submitted vulnerability reports. Participated in cybersecurity CTF competitions involving web exploitation, network security, and password-cracking challenges.