~/sobhan $ cat about.md

Whoami

Security researcher with a Master's in Computer Engineering. I operate at the intersection of breaking and building — finding vulnerabilities by day, writing software and teaching structural engineering by night.

Offensive Security

  • Web App Pentesting
  • API Security
  • Auth Bypass
  • IDOR / XSS / SQLi / SSRF

Engineering

  • Go / C / JS
  • REST & WebSocket
  • PostgreSQL
  • Docker

Academia

  • Structural Mechanics
  • Concrete Structures
  • Statics
  • Simulation Tools

Timeline

2024–now

Bug Bounty Hunter

Independent

Active on HackerOne & Bugcrowd. Specializing in web app vulnerabilities, API logic flaws, and authentication bypasses.

2022–now

Lecturer

Civil Engineering Dept.

Teaching statics, mechanic of materials, concrete structures design, and steel structures design. Developed interactive simulation tools for students.

2020–now

Software Engineer

Freelance

Building backend services in Go, full-stack web apps, and security tooling.

2025

M.Sc. Computer Engineering

University of Tehran