twistedmock Open to work

Offensive Security Researcher

Mahmud Hasan Sizan

A bug in every wave.

Top-1,000 hacker on HackerOne — credited by Apple, Goldman Sachs, SpaceX and GitHub.

Penetration testing · red teaming · application & vulnerability research  —  remote or relocating · GMT+6

Move to disturb the water

200 m The record

Six years of it, and the numbers hold up.

Every figure below was pulled live from the HackerOne API on 15 August 2026 — not from a CV. They're checkable: my profile is public.

0Reputation
0Global rank top 1,000 all-time
0Reports resolved
0Programs that thanked me
0Paid bounties
0Signal 81st percentile
0Impact top 16% for severity
0Years hunting
  • HackerOne ClearBackground-checked. Most researchers are not.
  • 7-month streakValid reports every month, Jan – Jul 2026.
  • Milestone Level IIIAll three tiers cleared, 2025–26 cycle.
  • 18 badgesSix of them distinct OWASP categories.

1 000 m Every wave · HackerOne

Thirty companies put their name to my findings.

Every mark below is a HackerOne program that accepted at least one of my reports as valid — the public ones. Rendered in a single ink, because down here everything glows the same. My private programs, most of my work, can't be named — that's further down.

And these are only the ones I'm allowed to name — about a sixth of the work. The rest is below.

2 000 m A second current · Bugcrowd

And ten more, on Bugcrowd.

The same work on a second platform. SpaceX, Atlassian, Twilio, the U.S. Department of Veterans Affairs — each took one of my reports into their public hall of fame. Three more are private, and stay that way.

4 000 m Water nobody can see

Eighty-four per cent of the work is invisible.

Twenty-eight of my sixty-seven programs are private — invitation-only, names withheld by HackerOne. They hold 2 896 of my 3 447 reputation. My public profile is the shallow end.

Deepest single program
#1of every hunter on it
48valid reports
1 075reputation — a third of my total

One private program. Ninety-four reports submitted, forty-eight recognised, first place overall. It cannot be named here, and it is the best evidence of what I do.

  • 684#4
  • 331#6
  • 324#23
  • 61#26
  • 57#33
  • 49#8
  • 32#21
  • 20 more≤24

5 000 m Acknowledged

Named by the people whose systems I broke.

Apple

×3 · web server security

Listed by name in Apple's official security acknowledgements — three separate months.

  • February 2026
  • August 2025
  • July 2025
support.apple.com/en-us/102774 ↗

Goldman Sachs

bounty awarded

Two bounties awarded in May 2026 — my most recent notable wins, one of them co-authored with fellow Bangladeshi hunter refat0g.

  • 3 May 2026
  • 24 Apr 2026 · collaboration

GitHub

security researcher

Report resolved September 2021, and the GitHub Security Researcher badge that came with it.

  • Resolved 28 Sep 2021

Adobe

5 valid reports

Four findings resolved inside six weeks in early 2023 — the densest run on any named program.

  • Feb – Mar 2023 · ×4 resolved

5 500 m What I find

Six OWASP categories, each confirmed by HackerOne's own badge.

Not a skills list. Badges are only issued on a valid report of that class.

  • A01InjectionSQL and command injection — untrusted input reaching an interpreter.
  • A02Broken AuthenticationSession and identity flaws — the class that ends in account takeover.
  • A04XML External EntitiesParsers coaxed into reading files and reaching internal services.
  • A05Broken Access ControlIDOR and privilege escalation — the object is there, the check is not.
  • A06Security MisconfigurationDefaults left in place, surfaces left open, secrets left reachable.
  • A07Cross-Site ScriptingStored, reflected and DOM-based execution in another user's session.

5 800 m Instruments

Reconnaissance at this scale needs tools nobody ships.

qshodan

Rust · github ↗

Extracts hosts from Shodan and defeats the platform's hard ceiling of 1 000 results per query by recursively subdividing the search — country, then city, then port — until every bucket fits under the limit. Validates, strips reserved ranges, deduplicates.

qport

Rust · github ↗

A port scanner that never touches the target. Resolves open ports out of Shodan's InternetDB at ~500 requests a second with rotating user agents, so an entire estate can be mapped without a single packet reaching the asset owner.

Attack Surface Monitoring

SaaS · in development

Continuous external attack-surface mapping, folding Crunchbase, Shodan, Censys, Whoxy and crt.sh into one picture with custom reconnaissance on top.

  • Rust
  • Python
  • Bash
  • Shodan
  • Censys
  • crt.sh
  • Whoxy

6 000 m Surface

Open to offensive-security work — penetration testing, attack-surface assessment, red teaming, vulnerability research. Remote, or relocating.

Available now  ·  full-time or contract  ·  remote worldwide or relocating  ·  GMT+6

mahmudhasan3801@gmail.com Download CV — one page, PDF

English — IELTS 8.0  ·  বাংলা  ·  हिन्दी  ·  اردو