Product security architect with an offensive background. Threat modeling, secure design, and attack surface reduction, plus the AI-native workflows that make it scale. I built Eidolon, an open-source security agent orchestrator, and I lead Canada's largest hacker community.
I'm a product security architect with an offensive background. My job is to threat model a design before it ships, find where the real attack surface is, and drive the architectural change that removes it, not to file a finding and move on.
I build the AI-native side of this too. I use Claude and OpenAI as core tools for threat analysis, abuse-case generation, and code review, and I wrote Eidolon, an open-source orchestrator that runs offensive security workflows with an AI agent in the loop, with real guardrails because an agent with real access needs them. I also run an offensive AI security workshop on attacking and defending agent-based systems.
The offensive grounding is real: 120+ validated vulnerabilities through HackerOne across web, API, cloud, and identity systems. Earlier, as a lead security architect, I built a company's security standards, detection, and architecture from scratch as it scaled. I lead DEF CON Toronto (DC416) and speak at SecTor and DEF CON Vancouver.
A trust boundary drawn wrong on a whiteboard costs an afternoon. The same mistake in production costs a quarter. I model abuse cases with the engineers who wrote the doc.
A scanner at default settings buries a team in noise until they stop reading it, which is worse than nothing. I'd rather ship five findings a week that are all real than five hundred that aren't.
Findings get traced to root cause, then checked for the same pattern everywhere else. One IDOR is a bug. The same authorization mistake in nine places is a design problem.
Open source (MIT), built and maintained in Python. It runs offensive security workflows with an AI agent in the loop, with per-engagement isolation, scope tokens, a hash-chained audit log, and three-tier command gating, because an agent with real access needs real guardrails. github.com/amir-hosseinpour/eidolon →
Hardware and firmware security research under the vendor's bug bounty program. UART console access, firmware extraction, then up through the cloud API and mobile app.
Burp Suite extension for automated OAuth2.0 and OIDC authorization-bypass detection, and a Nuclei template library for API and application vulnerability discovery.
Happy to talk whenever works for you.