Operators.
A small team of engineers and researchers. Owners of the outcome, not the invoice.
Primary contact for engagements and disclosure. Leads business operations and strategic partnerships at Xyrix. Active on API and infrastructure research.
First point of contact for new engagements. Owns the client conversation from initial outreach through scoping, working with founders and security teams to translate business risk into a concrete engagement plan.
Runs day-to-day operations at Xyrix: scheduling, engagement coordination, and ensuring every finding moves from disclosure to closure without slipping through the cracks.
Owns the offensive research pipeline: validation methodology, exploit chains, and final technical sign-off on every disclosure delivered.
Security researcher focused on application-layer logic, authentication surfaces, and API abuse patterns. Contributes to active research tracks and engagement delivery.
Lead Developer responsible for offensive tooling, internal automation, reporting systems, research infrastructure and engagement tooling supporting offensive security operations.
Research advisor to Xyrix. Currently inactive.
Request an audit.
Disclose a finding.
Private handling. No data accessed, modified, or retained beyond what is necessary to demonstrate the issue. Most messages are acknowledged within a few hours on business days.