April 18, 2026 marks exactly four years since I first joined VikingCloud as an Offensive Security Engineer I back in 2022.
Few years ago, I never would have imagined that a college dropout and skidd bug bounty hunter like me would land a proper role in the information security industry. While I had always manifested of breaking into cybersecurity, I had no clear idea of how to get there.
The early days of my bug bounty journey
When I first started in bug bounty hunting, I was completely lost. I had some experience with basic web application security (thanks to my time tinkering in underground communities) but beyond that, I had no structured knowledge. Vulnerabilities like IDOR and SSRF were foreign to me. I didn’t even know how to systematically look for vulnerabilities. Instead, I relied on scattered articles and twitter posts from more experienced hunters, trying to piece things together.
The struggle to learn
Between 2012 and 2015, learning about security vulnerabilities was far more difficult than it is today. Quality write-ups and blogs were scarce, and structured learning paths were almost nonexistent. The best way to learn was to immerse yourself in the bug bounty community. Twitter (now X) became my go-to platform for connecting with experienced hunters. Fortunately, there were pioneers like Bitquark, Neal Poole, Yuji Kosuga, Roy Castillo, and other OGs who shared their findings and techniques. Their insights were invaluable to beginners like me—I would read their posts, analyze their methods, and then apply them to real-world targets.
Finding bug bounty programs was a challenge
Unlike today, where multiple platforms offer structured bug bounty programs, back then, finding targets was an entirely different struggle. Only a handful of companies had bug bounty initiatives, and public programs were rare. My approach? Hunt on any website that seemed promising, especially those shared by other researchers on twitter. I also leveraged google dorking to uncover companies that quietly ran bug bounty programs or had security policies that allowed responsible disclosure.
Transitioning from bug hunter to engineer
Transitioning from independent bug hunting to corporate offensive security required a major mindset shift. In bug bounty hunting, success is often measured by finding high-severity impact bugs as fast as possible. As an Offensive Security Engineer, finding the flaw is only half the battle; Context Matters, you have to understand business risk, threat modeling, and internal architecture rather than focusing solely on isolated vulnerabilities. Methodology over Luck, relying on opportunistic findings gives way to thorough, coverage-based security assessments and comprehensive threat testing.
The resilience, creative problem-solving, and continuous learning mindset I built during those early, chaotic bug bounty days became my greatest strengths when stepping into an engineering role.
Looking back, the journey wasn’t easy. It was filled with uncertainty, frustration, and countless hours of trial and error. But those early struggles laid the foundation for everything that followed.
Four years into my role as an Offensive Security Engineer, I can say with confidence that persistence and community support made all the difference. To anyone just starting out—keep learning, keep hunting, and never underestimate the power of connecting with like-minded people.
— Japanese Proverbs

No comments:
Post a Comment