Pouya Darabi
Application Security Engineer · Security Researcher
I'm an Application Security Engineer and security researcher with more than a decade of experience in application security, penetration testing, vulnerability research, secure code review, and software engineering.
Over the years, I have discovered and responsibly disclosed security vulnerabilities affecting widely used products and services, including platforms from Meta (Facebook & Instagram), Google, Microsoft, Twitter/X, Yahoo, Adobe, Shopify, Square, and Mailchimp.
My research has included high-impact vulnerabilities involving authentication and authorization, business logic, CSRF protection bypasses, privilege escalation, access control, and application security controls. Some of my findings have been publicly documented and covered by international security and technology publications, while many others remain private.
What matters most to me is the real-world impact of this work: helping secure products that millions of people and businesses rely on every day.
Professionally, my work goes beyond vulnerability discovery. I perform application and API penetration testing, source code review, vulnerability assessment, remediation validation, and security engineering, working closely with developers, DevOps, infrastructure, and security teams to identify risks and build practical solutions.
My software engineering background gives me an important perspective on security: I don't only look at how an application can be broken — I understand how it is built, why vulnerabilities happen, and how they can be fixed without unnecessarily slowing down engineering teams.
Areas of Focus
Application Security · Web & API Security · Penetration Testing · Vulnerability Research · Secure Code Review · Authentication & Authorization · Business Logic Security · DevSecOps · Security Automation
Security Research
Selected organizations that have acknowledged my vulnerability research include:
Meta · Google · Microsoft · Twitter/X · Yahoo · Adobe · Shopify · Square · Mailchimp
Only a selection of my vulnerability research has been publicly disclosed. Public research and technical write-ups are available throughout this blog.
Profiles & Contact
HackerOne:
@supernatural
LinkedIn: linkedin.com/in/pouyadarabi
GitHub: github.com/pouyadarabi
X / Twitter: @pouyadarabi
For professional or security-related inquiries, feel free to contact me.