Product security engineer with an attacker mindset. Manual security reviews, threat modeling, and pentesting, and I go deep on authentication and authorization: SAML, OAuth, OIDC. I built Eidolon and a Burp extension for OAuth and OIDC bypass, and I lead Canada's largest hacker community.
I'm a product security engineer with an attacker mindset. I do the manual work, design reviews, threat modeling, secure code review, and penetration testing, and I go deepest on the thing identity systems live or die on: authentication and authorization. I review SAML, OAuth, and OIDC for the flaws scanners never find, and I wrote a Burp extension that automates OAuth and OIDC authorization-bypass detection.
The AI side is real too. I assess AI-integrated architectures and LLM security, and I built Eidolon, an open-source orchestrator that automates security testing by driving an agent with real guardrails. I teach where agent systems break, prompt injection, tool-permission scoping, credential handling, in a hands-on workshop.
The offensive grounding is 120+ validated vulnerabilities through HackerOne, mostly authorization bypass and privilege escalation, and I have led product security incidents end to end. I do it in the open, too: I speak at SecTor and DEF CON, I open-source my tooling, and I lead DEF CON Toronto (DC416).
A trust boundary drawn wrong on a whiteboard costs an afternoon. The same mistake in production costs a quarter. I model abuse cases with the engineers who wrote the doc.
A scanner at default settings buries a team in noise until they stop reading it, which is worse than nothing. I'd rather ship five findings a week that are all real than five hundred that aren't.
Findings get traced to root cause, then checked for the same pattern everywhere else. One IDOR is a bug. The same authorization mistake in nine places is a design problem.
A Burp Suite extension I built that automates OAuth2.0 and OIDC authorization-bypass detection across API surfaces. Auth is where identity systems break, so I made the bug class easier to find.
Open source (MIT), built and maintained in Python. A security orchestrator that automates testing by driving an AI agent, with per-engagement isolation, scope tokens, and three-tier command gating, so the agent earns trust one step at a time. github.com/amir-hosseinpour/eidolon →
SecTor 2025 and DEF CON Vancouver (API attack chains and OAuth2.0 exploitation), plus a firmware teardown of a robot vacuum under the vendor's bug bounty program. I share the work rather than hide it.
Happy to talk whenever works for you.