Security @ Meta · London, UK

Sahil Ahamad

Application security researcher and bug bounty hunter — hunting independently, and running triage from inside the program.

I hunt bugs as an independent researcher, and I work the other side of the same process at Meta — external researcher reports from triage through to remediation with the teams that own the code.

Most people in this field see one side or the other. Running a program changes how you read a report, and hunting changes how you triage one. That is the perspective I write from.

HackerOne profile →

#26
Peak HackerOne leaderboard rank, 2019
$750
First bounty — PayPal
3.2K
Medium followers
847
GitHub stars — SwiftnessX

Scope

Recon & attack surface

Asset discovery, subdomain pipelines, DNS resolution, port scanning and cloud storage bucket auditing. Mapping what an organisation actually exposes before testing any of it.

Web & API testing

Broken access control and IDOR, authentication bypasses, subdomain takeover and data exposure, across public and private enterprise programs.

Triage & remediation

Running bug bounty programs from the inside — reading incoming reports, reproducing them, and driving fixes with the product teams that own the affected service.

Hall of fame

PayPal Independent Bounty awarded
PlayStation HackerOne Acknowledged
Mapbox HackerOne Acknowledged
Kaspersky HackerOne Acknowledged
Linktree HackerOne Acknowledged
eToro HackerOne Acknowledged
OWOX HackerOne Acknowledged

Full report history on HackerOne →

Experience

  1. 2022 — Present

    Security

    Meta · London
    • Bug bounty program: external researcher reports from triage through to remediation.
    • Third-party vulnerability management, coordinating fixes with owning product teams.
  2. Mar 2019 — Feb 2022

    Security Engineer II

    Zomato · Gurgaon
    • Managed the Zomato bug bounty program on HackerOne and triaged incoming disclosures.
    • Hardened core microservices, mobile endpoints and web infrastructure serving millions of daily requests.
    • Internal threat modelling, code audits, and automated security checks in CI/CD.
  3. 2018

    Live hacking event, Kyiv

    HackenProof

    Invited to hack on site after solving the HackenProof CTF at Hacken Cup 2018.

  4. Jul 2018 — Mar 2019

    Security Engineer

    Nykaa
    • Application vulnerability assessments and penetration testing across e-commerce web and mobile platforms.
    • Secured payment gateway integrations, user data stores and internal admin dashboards against IDOR and unauthorised access.
  5. Earlier

    Client application auditing

    SecurityEscape

    Where Swiftness originated, built for client auditing work.

  6. 2013 — Present

    Independent researcher

    HackerOne · Bugcrowd · Intigriti · HackenProof

    Subdomain takeovers, broken access control and IDOR, authentication bypasses and data exposure, across public and private enterprise programs.

Tooling

SwiftnessX

Co-created with Rishiraj Sharma

Cross-platform note-taking and target-tracking app for penetration testers. Checklist management by target type, per-target notes for endpoints and recon data, and importable OWASP testing checklists. Originally a macOS app built at SecurityEscape, later rebuilt from scratch on Electron for Windows and Linux.

847 stars · GPL-3.0 · Electron

Recon-My-Way

Open-source automation scripts and workflows for asset discovery, DNS resolution, port scanning and cloud storage bucket auditing.

Community repositories

Wordlists, Android reverse-engineering setup notes (class-dump-z), and collaborative security documentation.

Writing

On this site

All posts →

Contact