offensive security · vulnerability research
I'm Matthew Zamat — an application security manager and offensive security professional. I find and exploit critical flaws in web, API, and mobile targets, with 300+ accepted vulnerabilities and P1 criticals on some of the most hardened programs in the industry.
Capabilities
Internal/external network pentesting and red team engagements — phishing assessments, adversary simulation, and custom payload development.
Deep expertise in web and API vulnerability discovery. 300+ accepted bugs with P1 criticals on hardened targets — focused on access control and authentication flaws.
Secure code review across Java, Python, and JavaScript. SAST/DAST/SCA integration into CI/CD pipelines — shifting security left in the SDLC.
Static and dynamic analysis of iOS, macOS, and Android applications — identifying hardcoded secrets, weak crypto, and hidden functionality.
Building custom scripts, scanners, and payloads for assessments — automating reconnaissance, vulnerability scanning, and exploitation workflows.
Mapping findings to MITRE ATT&CK, OWASP, and CWE — supporting compliance efforts aligned with FISMA and NIST 800 series standards.
Experience
Aug 2025 — Present
OnDefend — District of Columbia
Jan 2025 — Aug 2025
SIXGEN — Arlington
Jan 2023 — Jan 2025
Synack
Jun 2019 — Present
Bugcrowd / HackerOne
Research & writeups
Technical deep-dives on the vulnerabilities I find — how they work, how I found them, and how to fix them.
Get in touch