josh_ get in touch

// software developer · it security researcher

I build systems. Then I take them apart.

Seven-plus years shipping full-stack products — TypeScript, Rust, Go, Solidity — and breaking the ones that deserve it. Security Champion, MEV bot author, responsible-disclosure practitioner.

josh@dev — whoami
01

Profile

I'm Josh — a developer who thinks like an attacker and an attacker who ships like a developer. Most of my career I've built enterprise platforms end to end: architecture, frontend, backend, pipelines, production. The rest of the time I've been on the other side of the same systems — testing web applications, reviewing code, reversing firmware, and reporting what I find through responsible disclosure.

The two halves feed each other. Building a DeFi platform to $10M peak TVL with a lean team taught me what auditors actually look for; finding account takeovers and data exposure in production systems taught me how to build so those classes of bugs never make it out the door.

7+years shipping production software
$10Mpeak TVL on a DeFi platform I co-built
4vuln classes found & responsibly disclosed
9k+community grown around a product I ran
02

Experience

  1. 2025 — now

    Founder & Engineer · independent venture

    Co-built and operated a production-grade DeFi platform end to end with a 2–5 person team: React frontend, backend services, smart contracts, infrastructure. Worked directly with external security auditors to harden the platform and drive remediation.

    • Smart contracts underpinning core product logic — ~$10M peak total value managed
    • Owned the full delivery lifecycle: CI/CD, observability, database design, operations
    • Grew an engaged community past 9,000 members while keeping the platform live
    SolidityFoundryReactEVMsecurity audits
  2. 2024

    Senior Software Engineer · ESG analytics SaaS

    Frontend modernization of a legacy enterprise platform inside a ~10-engineer team — the Angular/TypeScript rewrite, complex analytics workflows for enterprise customers, plus backend features in PHP and Symfony.

    AngularTypeScriptPHPSymfony
  3. 2022 — 2023

    Software Engineer & Security Champion · travel & booking platforms

    Enterprise applications for customer-facing booking systems — Angular, reusable React Web Components, REST API integrations, Azure DevOps pipelines. Took on security reviews, threat identification and remediation across customer-facing systems.

    AngularReactPythonAzure DevOpssecure SDLC
  4. 2018 — 2021

    Fullstack Engineer · digital commerce agency

    Enterprise e-commerce for B2B/B2C clients — Magento 2 and Shopware implementations, custom Angular/React frontends, platform migrations with zero data loss. Replaced ORM-heavy hot paths with optimized SQL and made critical queries fast again.

    Magento 2ShopwareSQLReact
  5. 2021

    IT Specialist — Application Development · certified, Germany

    Formal apprenticeship track (Fachinformatiker Anwendungsentwicklung), graduated 2021.

03

Security work

Offensive security is where my engineering background pays off: I read the code before I poke the endpoint. Web application testing, secure code review, binary and firmware work — always with an eye on impact and remediation, not leaderboard points.

HIGH

Account takeover

Authentication-flow flaws chained into full account compromise on production systems.

HIGH

Sensitive data exposure

Endpoints and responses leaking data they should never have — found, reported, fixed.

MED

Cross-site scripting

Stored and reflected XSS in customer-facing applications, with working PoCs.

MED

Subdomain takeover

Dangling infrastructure claimed before someone less friendly did.

→ every finding reported through responsible disclosure · coordinated with vendors until patched

// web & application

  • OWASP Top 10 — testing & remediation
  • Burp Suite & recon tooling
  • Secure code review (TS, PHP, Java, Solidity)
  • Threat modeling & secure SDLC

// low level

  • Binary analysis & low-level debugging
  • Firmware reverse engineering
  • Fuzzing & crash triage

// on-chain

  • Smart-contract security review
  • MEV & keeper-bot economics
  • Collaboration with external auditors
04

Projects

05

Open source

A selection from github.com/jjoshm — the public slice of what I build. Client work and current research stay private.

06

Stack

languages
TypeScriptPythonRustGoSolidityPHPJavaSQL
frontend
ReactAngularWeb ComponentsThree.jsHTML5 / CSS3
backend
Node.jsPythonRustSymfonyREST APIsPostgreSQL
chain
EVMFoundryethers / alloyMEV & keeper infraNEAR
security
Burp SuiteOWASPfuzzingGhidra-class REbinary analysis
ops
LinuxDockerGitHub ActionsAzure DevOpsNeovim
07

Contact

Open to senior engineering and security roles — worldwide remote, or on-site in the EU. Also happy to talk shop about MEV, agent tooling, or a finding you'd like a second pair of eyes on.

security-sensitive? ask for my PGP key first.