Application security engineer who builds tools, not just findings. I wire security into CI/CD, threat model the hard changes, and build the agent tooling that does the first pass. I wrote Eidolon, an open-source orchestrator that drives Claude Code, and I lead Canada's largest hacker community.
I'm an application security engineer who builds the tooling. I wire SAST, DAST, SCA, and secret scanning into CI/CD so findings land where developers already work, threat model architectural changes, and run triage that retires risk instead of growing a backlog.
The part I care about most is the agent side. I build agent tooling, not just use it. I wrote Eidolon, an open-source orchestrator that drives Claude Code through security workflows, with per-engagement isolation, scope tokens, and three-tier command gating, because an agent with write access needs to earn trust one step at a time. I've thought hard about where agentic systems break, prompt injection, tool-permission scoping, credential handling, and I teach it in a hands-on workshop.
Under all of it is an offensive background: 120+ validated vulnerabilities through HackerOne, deep OWASP and CWE work, which is most of why I can tell a real finding from a plausible one. I lead DEF CON Toronto (DC416) and speak at SecTor and DEF CON Vancouver.
A trust boundary drawn wrong on a whiteboard costs an afternoon. The same mistake in production costs a quarter. I model abuse cases with the engineers who wrote the doc.
A scanner at default settings buries a team in noise until they stop reading it, which is worse than nothing. I'd rather ship five findings a week that are all real than five hundred that aren't.
Findings get traced to root cause, then checked for the same pattern everywhere else. One IDOR is a bug. The same authorization mistake in nine places is a design problem.
Open source (MIT), built and maintained in Python. An orchestrator that drives Claude Code through security workflows, with per-engagement isolation, scope tokens, a hash-chained audit log, and three-tier command gating, because an agent with repo access needs to earn trust one step at a time. github.com/amir-hosseinpour/eidolon →
Hardware and firmware security research under the vendor's bug bounty program. UART console access, firmware extraction, then up through the cloud API and mobile app.
Burp Suite extension for automated OAuth2.0 and OIDC authorization-bypass detection, and a Nuclei template library for API and application vulnerability discovery.
Happy to talk whenever works for you.