Public author profile

Security engineering · Vulnerability research · Offensive security · Automation

Incredincomp

Security engineering, vulnerability research, and practical offensive testing.

I work across enterprise networks, identity, applications, cloud infrastructure, and security automation—finding weaknesses, validating meaningful risk, and translating findings into remediation that works in production.

5+ years in regulated financial-services environmentsEnterprise network, identity, and security-control ownershipFive Apple security advisory acknowledgements

What I help teams decide

Turn noisy security signals into decisions your team can act on.

  • Vulnerability triage that separates real risk from feed noise.
  • Enterprise network, identity, and security-control review grounded in production operations.
  • Vulnerability assessment and threat validation with evidence, assumptions, and remediation paths.

Public proof

Referenced in five Apple security advisory acknowledgements related to UIKit reports.

Proof points

Security work that teams can use.

Enterprise security engineering

Five-plus years in regulated financial-services environments, owning practical network, identity, and security controls.

Vulnerability research and validation

Assess exploitability, emulate threats, validate controls, and turn evidence into remediation teams can execute.

Security automation and tooling

Build custom Python, PowerShell, Bash, and API-driven tools for repeatable testing and evidence collection.

Decision process

How I turn security signals into decisions

What I help teams do

Connect enterprise security engineering, vulnerability research, and offensive validation to actions teams can execute.

How I work

Keep source links, assumptions, and reviewer state visible so security decisions can be checked quickly and communicated clearly.

Where it fits

Best for vulnerability triage, cloud/release review, and product-security advisory work when teams need a sharper decision path instead of more alerts.

Supporting proof

Public evidence behind the recommendations

  • Enterprise network and identity security-control ownership
  • Vulnerability assessment, threat emulation, and incident-response judgment
  • Application-security analysis and responsible vulnerability disclosure
  • Apple Product Security — Additional Recognition, 2026

Recognition

Apple acknowledgement references

Supporting signal from the same reporting trail.

Apple security acknowledgements

Apple publicly credits incredincomp in five security advisories covering iOS/iPadOS, macOS, tvOS, watchOS, and visionOS. This is independent recognition, not employment or a CVE assignment.

Bug bounty and vulnerability reporting

Responsible vulnerability reporting with safe reproduction, exploitability analysis, evidence, and useful remediation detail.

Independent work

Independent tools and community reach

Supporting signals that show practical tooling and public security-education reach.

Developer tooling

Explorer Dates

Created and launched a Visual Studio Code extension that adds file modification dates and context directly to the VS Code Explorer.

VS Code Marketplace · 2.0k+ installs

View on VS Code Marketplace

Community signal

PortSwigger featured an @incredincomp post

Screenshot of a PortSwigger LinkedIn post featuring an @incredincomp Burp Suite education post.

A public @incredincomp post about teaching Burp Suite was featured by PortSwigger in a LinkedIn update about security education.

Next steps

Need help turning security signals into action?

Bring vulnerability triage questions, cloud and release review decisions, product-security or advisory findings, or AI-assisted security operations queues. You get source-linked reasoning, clear assumptions, and practical remediation paths.

Curated vulnerability intelligence and practical security automation by Incredincomp.