I am Bruce Kang, an offensive security engineer with approximately five years of experience identifying and exploiting vulnerabilities across enterprise environments. My work focuses on adversarial assessment of web applications, APIs, cloud platforms, and internal networks, along with the research and tooling that supports it.

Focus Areas

  • Web application and API security. Manual testing, source code review, and threat modeling, with emphasis on the vulnerability classes that automated scanners do not reliably surface.
  • Cloud security across AWS, Azure, and GCP. IAM trust policy abuse, exposed storage and data services, insecure serverless functions, and identity-based pivoting between accounts.
  • Internal and external network security. Active Directory and Entra ID attack chains, lateral movement, perimeter assessment, and end-to-end attack path mapping from initial foothold to domain compromise.
  • Vulnerability research. Root cause analysis, exploitability assessment, and proof-of-concept development to validate severity ratings and demonstrate impact.
  • Tooling and automation. Python and Bash utilities that accelerate discovery, scanning, and reporting workflows during assessments.

Experience

  • Praetorian (August 2022 to March 2026), Senior Security Engineer. Approximately 50 enterprise assessments per year spanning web applications, APIs, cloud infrastructure, and internal networks.
  • Synack (July 2021 to July 2022), Security Researcher on the Synack Red Team. Specialized in authorization and access control vulnerabilities. Authored two articles on the Synack blog covering OWASP Top 10 categories.
  • Avanade (April 2021 to July 2021), Security Analyst Intern. Threat triage, malware and phishing analysis, and proactive threat hunting across enterprise environments.

Certifications

OSCE3, OSCP, OSWE, OSED, OSEP, AWS Solutions Architect (Associate), CompTIA Security+, Network+, A+, and Microsoft Azure Fundamentals (AZ-900).

Education

B.S. in Information Technology, University of Washington, 2021.

Elsewhere

Source for this site is available at github.com/bk-security/bk-security.github.io.