Offensive security · vulnerability research

Matthew Zamat

Application Security Manager and Offensive Security Researcher

I find and exploit critical vulnerabilities in web, API, mobile, and hardware systems, with a focus on the access control and authentication flaws that automated tooling misses. Over 1,000 findings submitted, and a top-20 all-time ranking on HackerOne.

Findings submitted
1,000+
HackerOne, all time
Top 20
Published CVE
8.9
Certified
OSCP+

AI-assisted testing, validated by hand

I build AI-assisted workflows that widen coverage without loosening rigor. The automation surfaces candidates; nothing ships as a finding until it is manually reproduced with a working proof of concept.

That validation gate is the point. It is what separates useful acceleration from a pile of plausible-sounding false positives.

  • LLM-assisted reverse engineering

    Pairing Ghidra with large language models over MCP to triage stripped iOS, macOS, and Android binaries in a single sitting instead of a full day.

  • Automated authorization testing

    Internal tooling that replays token-swapped requests across endpoint matrices and diffs responses to surface broken object level authorization at scale.

  • Agent-based testing platform

    An autonomous, agent-based offensive platform combining LLM-driven planning with specialized workers for HTTP, IDOR, browser, and authentication flow testing.

  • Validation and recon gates

    Engineered checkpoints requiring manual reproduction and a working proof of concept for every AI-surfaced finding before it reaches a client.

What I test

Web & API security

Deep specialization in access control and authentication flaws across REST, GraphQL, and single-page applications. This is where most of my critical findings come from.

IDOR / BOLA Auth bypass GraphQL Business logic

Mobile & reverse engineering

Static and dynamic analysis of iOS, macOS, and Android applications: hardcoded secrets, weak crypto, SSL pinning bypass, and hidden functionality in stripped binaries.

Ghidra Frida Objection JADX / IL2CPP

Hardware & firmware

Hardware and IoT assessments, including firmware extraction over UART and JTAG, binary triage, and analysis of the services running underneath the device.

UART / JTAG Firmware IoT Binary triage

Red team & network

Internal and external penetration testing, adversary simulation, phishing assessments, and custom payload development against externally exposed networks.

Cobalt Strike Metasploit Nmap Social engineering

Secure code review

Reading and analyzing Python, Java, C#, and JavaScript codebases to find flaws at the source, plus SAST, DAST, and SCA integration into CI/CD pipelines.

Python / Java C# / JavaScript SAST / DAST CI/CD

Frameworks & compliance

Mapping findings to MITRE ATT&CK, OWASP, and CWE to deliver actionable remediation guidance, supporting compliance aligned with FISMA and the NIST 800 series.

MITRE ATT&CK OWASP NIST 800 FISMA

Where I've worked

Full résumé

Aug 2025 to Present

Application Security Manager

OnDefend · Washington, DC

  • Lead the application penetration testing practice, scoping and executing advanced web, mobile, API, and hardware assessments that simulate real adversarial tradecraft
  • Designed and deployed AI-assisted workflows across the offensive lifecycle, pairing Ghidra with large language models over MCP to triage stripped binaries
  • Built internal tooling that automates cross-user authorization testing by replaying token-swapped requests across endpoint matrices
  • Engineered validation gates requiring manual reproduction and a working proof of concept for every AI-surfaced finding before client delivery

Jan 2025 to Aug 2025

Offensive Cyber Operator

SIXGEN · Arlington, VA

  • Performed internal and external penetration testing across externally exposed networks, identifying vulnerabilities and recommending mitigations
  • Discovered and published CVE-2025-62586
  • Operated Cobalt Strike, Metasploit, Burp Suite, PowerSploit, and Nmap in red team engagements, writing custom scripts and crafting payloads
  • Supported compliance efforts aligned with FISMA and the NIST 800 series

Jan 2023 to Jan 2025

Red Team Penetration Tester

Synack Red Team · Remote

  • Conducted security audits and penetration tests of web applications and source code on Synack's vetted, invite-only researcher platform
  • Executed complex security testing with commercial tooling and personally developed open source scripts
  • Authored detailed, accessible findings reports and led peer review among researchers

Jun 2019 to Present

Independent Security Researcher

Apple Security Bounty · HackerOne · Google VRP

  • Over 1,000 findings submitted, with a top-20 all-time global ranking on HackerOne
  • Multiple accepted findings across Apple platforms and services, with public credit in Apple's security acknowledgements
  • Reported access control and AI prompt injection findings to the Google Vulnerability Reward Program
  • Operates an independent Maryland LLC for security research and consulting work

Jun 2019 to Jan 2023

Scientist, Upstream Process Development

Novavax, then Catalent · Maryland

  • Designed and executed statistically defined DOE studies to develop high-yielding, scalable vaccine production processes during COVID-19 vaccine development
  • Developed and qualified ddPCR, qPCR, RT-qPCR, and ELISA methods on gene therapy samples in a cGMP environment
  • The methodical, evidence-first habits from bench science are the same ones that make a good security researcher

Let's talk.

Open to conversations about application security work, research collaboration, and interesting bugs.