Open to opportunities
Kaan Dedeoğlu

Kaan Dedeoğlu

Computer Engineering graduate working full time on offensive application security. I hunt authorization and access-control flaws in large open-source products: read the code, find the gap, then prove it with an end-to-end PoC before it becomes a report. Highest severity validated to date is Critical, CVSS 9.6. The tooling and methodology behind that work are my own. Before all of it: two systems and networking internships and an IEEE-published graduation project.

HackerOne LinkedIn contact@kaandedeoglu.com
01 Education
BSc in Computer Engineering
Sep 2020 — Jun 2025
Eskişehir Technical University, Turkey — Language of Instruction: English
Prof. Dr. Fuat Sezgin Fen Lisesi
Sep 2016 — Jun 2020
Science High School — Silivri, Istanbul, Turkey
02 Experience
Independent Security Researcher
Jul 2025 — Present
HackerOne — @dedephus — Remote
  • Highest severity validated to date: Critical, CVSS 9.6
  • Submitted 58 reports across 12 bug bounty programs since April 2026. Every report ships with a reproducible PoC and a severity argued in CVSS terms; the first bounty was awarded in August 2026.
  • How I work: read the open-source codebase for authorization gaps and unguarded internal clients, then prove each candidate with a working end-to-end PoC on a local deployment. I do not report anything I cannot prove.
  • Built and maintain the-grind, the research platform this work runs on — reconnaissance, exploitation, adversarial validation and report drafting in one continuous loop rather than a scanner. Detail under Projects.
  • Program names and technical detail stay out of public writing until the vendor discloses the report. None of the findings to date are disclosed, so none of them are described here.
  • Ramped up full time from July 2025 — web application security fundamentals, systematic study of disclosed HackerOne reports and public vulnerability research, and a repeatable testing methodology — before the first submission in April 2026.
IT Systems Intern
Oct — Dec 2024
Eskişehir Technical University — IT Department, Systems & Networking
  • Deployed a production-like DSpace 8 backend for the university’s digital library, with two other interns: Java 17, Maven, Ant, PostgreSQL and Apache Solr on an Ubuntu 22.04 VM provisioned by the IT staff.
  • Hardened the database layer: a dedicated PostgreSQL role, connection security through pg_hba.conf, and the pgcrypto extension for UUID support.
  • Configured Solr cores for DSpace search, integrated MaxMind GeoIP for usage statistics, and ran the application as a Spring Boot service with its own properties and logging.
  • Configured HTTPS through an Apache reverse proxy with a Let’s Encrypt certificate, and automated daily indexing, media filtering and checksum verification with cron.
IT Systems Intern
Jul — Aug 2024
Creentech — Istanbul, Turkey — Systems & Network Department
  • Administered Debian-based Linux systems: user and permission management, sudo policy, APT package management, systemd services, and cron automation scripted in Bash.
  • Assisted the network team with FortiGate firewall policies, VLAN setup, static routing, web filtering and AP/switch integration.
  • Worked alongside production monitoring in Grafana and Zabbix, virtualization on VMware and Nutanix, and Active Directory administration.
03 Training & Development
Garanti BBVA Technology Security Academy
Oct 2023 — Feb 2024
Enterprise Technology & Cybersecurity Training Program — Patika.dev
  • Top 20 of 3,600 applicants — 450 admitted, narrowed to 20
  • Covered Linux internals, network protocols and enterprise application security, with threat modeling and secure architecture review applied to real-world systems.
04 Certifications
Wiz
Bug Bounty Masterclass
Apr 2026
OWASP Top 10 Web App Security Bug Bounty
Udemy
Sıfırdan Bug Bounty ve Web Uygulama Güvenliği
Jul 2025
Web App Security OWASP Top 10
Cisco
NDG Linux Unhatched
Feb 2025
Linux
Cisco
Introduction to Cybersecurity
Jan 2025
Cybersecurity
TryHackMe
Pre Security
Mar 2024
Network Fundamentals Linux Fundamentals
TryHackMe
Introduction to Cyber Security
Feb 2024
Cybersecurity
Garanti BBVA Teknoloji
Patika.dev & Garanti BBVA Güvenlik Akademisi
Dec 2023
App Security Linux Networking
05 Projects
the-grind — Autonomous Security Research Platform
Apr 2026 — Present
Python, TypeScript, Bash, Caido, Docker — private repository, walkthrough on request
OSTEODEEP — AI-Driven Bone Health Assessment with Chatbot Integration using X-rays
Jan 2024 — Jun 2025
Graduation Thesis — Eskişehir Technical University
IEEE Published TÜBİTAK 2209-A Funded
06 Technical Skills
Security
Web App Security OWASP Top 10 IDOR / BOLA / BFLA SSRF SQL & NoSQL Injection Auth & OAuth/SAML Race Conditions Source-Code Review CVSS
Tools
Caido Burp Suite ffuf nuclei interactsh Playwright
Systems
Linux Administration Networking Docker Git PostgreSQL Reverse Proxies CI/CD
Programming
Python TypeScript Java (Spring Boot) Bash SQL