Since January 2025 I have been a member of the Synack Red Team (SRT).
What the Synack Red Team is
The Synack Red Team is a private, global community that only vetted security researchers can join. Its members perform penetration testing and vulnerability research for major organisations across web applications, mobile applications and infrastructure.
- Vetted. Joining involves a multi-step vetting process (skill assessments, background checks and more); historically fewer than 10% of applicants are accepted.
- Global. Researchers span six continents and more than 80 countries.
- Crowdsourced. Members work remotely, on their own schedule. It resembles bug bounty in places, but Synack sets a higher quality bar.
Official site: Synack Red Team
My involvement
As a researcher I carry out vulnerability research and red-team work against in-scope targets. I can’t share specifics of individual engagements due to confidentiality, but I bring the same attacker’s mindset I’ve built up in my day job (vulnerability assessment and penetration testing).