Scan a product. Trace the companies behind it, from the brand on the package to the parent company at the top of the ownership chain. Explore verified environmental, labor, human-rights, political, tax, supply-chain, and governance signals. Open every source and read the exact evidence behind each claim. Votello keeps uncertainty visible, explains how each signal affects the score, and never turns missing evidence into a clean bill of health. The result is not a shopping verdict. It is a transparent map that helps you decide for yourself.
// software developer · it security researcher
I build systems. Then I take them apart.
Seven-plus years shipping full-stack products — TypeScript, Rust, Go, Solidity — and breaking the ones that deserve it. Security Champion, MEV bot author, responsible-disclosure practitioner.
Profile
I'm Josh — a developer who thinks like an attacker and an attacker who ships like a developer. Most of my career I've built enterprise platforms end to end: architecture, frontend, backend, pipelines, production. The rest of the time I've been on the other side of the same systems — testing web applications, reviewing code, reversing firmware, and reporting what I find through responsible disclosure.
The two halves feed each other. Building a DeFi platform to $10M peak TVL with a lean team taught me what auditors actually look for; finding account takeovers and data exposure in production systems taught me how to build so those classes of bugs never make it out the door.
Experience
-
2025 — now
Founder & Engineer · independent venture
Co-built and operated a production-grade DeFi platform end to end with a 2–5 person team: React frontend, backend services, smart contracts, infrastructure. Worked directly with external security auditors to harden the platform and drive remediation.
- Smart contracts underpinning core product logic — ~$10M peak total value managed
- Owned the full delivery lifecycle: CI/CD, observability, database design, operations
- Grew an engaged community past 9,000 members while keeping the platform live
SolidityFoundryReactEVMsecurity audits -
2024
Senior Software Engineer · ESG analytics SaaS
Frontend modernization of a legacy enterprise platform inside a ~10-engineer team — the Angular/TypeScript rewrite, complex analytics workflows for enterprise customers, plus backend features in PHP and Symfony.
AngularTypeScriptPHPSymfony -
2022 — 2023
Software Engineer & Security Champion · travel & booking platforms
Enterprise applications for customer-facing booking systems — Angular, reusable React Web Components, REST API integrations, Azure DevOps pipelines. Took on security reviews, threat identification and remediation across customer-facing systems.
AngularReactPythonAzure DevOpssecure SDLC -
2018 — 2021
Fullstack Engineer · digital commerce agency
Enterprise e-commerce for B2B/B2C clients — Magento 2 and Shopware implementations, custom Angular/React frontends, platform migrations with zero data loss. Replaced ORM-heavy hot paths with optimized SQL and made critical queries fast again.
Magento 2ShopwareSQLReact -
2021
IT Specialist — Application Development · certified, Germany
Formal apprenticeship track (Fachinformatiker Anwendungsentwicklung), graduated 2021.
Security work
Offensive security is where my engineering background pays off: I read the code before I poke the endpoint. Web application testing, secure code review, binary and firmware work — always with an eye on impact and remediation, not leaderboard points.
Account takeover
Authentication-flow flaws chained into full account compromise on production systems.
Sensitive data exposure
Endpoints and responses leaking data they should never have — found, reported, fixed.
Cross-site scripting
Stored and reflected XSS in customer-facing applications, with working PoCs.
Subdomain takeover
Dangling infrastructure claimed before someone less friendly did.
→ every finding reported through responsible disclosure · coordinated with vendors until patched
// web & application
- OWASP Top 10 — testing & remediation
- Burp Suite & recon tooling
- Secure code review (TS, PHP, Java, Solidity)
- Threat modeling & secure SDLC
// low level
- Binary analysis & low-level debugging
- Firmware reverse engineering
- Fuzzing & crash triage
// on-chain
- Smart-contract security review
- MEV & keeper-bot economics
- Collaboration with external auditors
Projects
Open source
A selection from github.com/jjoshm — the public slice of what I build. Client work and current research stay private.
Lyris
100% offline period & cycle tracker built with Flutter — local-only SQLite storage, no accounts, no cloud. Clue-inspired prediction engine with recency-weighted cycle modeling and a read-only partner mode over local WiFi.
source ↗olympusdao-clearinghouse-bot
MEV keeper bot for OlympusDAO's Clearinghouse — mempool-aware, latency-sensitive, built on the Artemis framework.
source ↗olympusdao-heartbeat-bot
Keeper bot keeping protocol heartbeats alive on-chain — async Rust, provider abstraction, production uptime.
source ↗pi-nousresearch-extension
Provider extension for the pi AI coding-agent ecosystem — OAuth device-code login, token refresh, dynamic model loading against the Nous Research inference API.
source ↗hashassine
Smart contracts on NEAR Protocol — a learning exercise in on-chain game logic and contract architecture.
source ↗Stack
Contact
Open to senior engineering and security roles — worldwide remote, or on-site in the EU. Also happy to talk shop about MEV, agent tooling, or a finding you'd like a second pair of eyes on.
security-sensitive? ask for my PGP key first.