Dennis Mwanzia
@dennismwanzia
Cybersecurity and application security researcher bridging development and security to remediate vulnerabilities.
What I'm looking for
I’m a results-driven cybersecurity professional with 5+ years of experience in software engineering, secure architecture, and vulnerability remediation. I focus on identifying critical security flaws and implementing scalable defenses, especially where application design and real-world misuse intersect.
As a freelance Security Researcher at Deutsche Telekom AG and Artsy, I’ve discovered and responsibly disclosed high-severity issues that directly strengthened security posture. I reported sensitive data exposure from a publicly exposed endpoint, uncovered privilege escalation via unauthenticated API endpoints, and developed a WAF-bypass technique exploiting regex filter weaknesses to access internal files—then proposed hardening measures to mitigate the risk.
My work also includes responsible disclosure and remediation collaboration: at Reddit (via HackerOne), I found a logic flaw that could enable malicious account deletion and supported fixes through RBAC and destructive-action confirmations. I’ve also identified client-side flaws in Jira Cloud and Confluence Cloud involving improper user output encoding, and I’m passionate about bridging development and security to build resilient systems.
Experience
Work history, roles, and key accomplishments
Security Researcher
Uncovered a critical proxy-system misconfiguration that exposed protected API endpoints, enabling unauthorized access to sensitive customer order details (including PII and real-time location via Google Maps integration). Demonstrated an exploit chain that could have led to leakage of 3 million customer records and worked with the security team to implement immediate safeguards preventing a large-
Security Researcher
Identified and reported a critical misconfiguration that leaked sensitive environment variables via a publicly exposed endpoint, and collaborated on remediation to prevent unauthorized access. Discovered unauthenticated API endpoints enabling privilege escalation, and developed a WAF-bypass technique exploiting regex filter weaknesses to access restricted internal files; contributed to hardening m
Security Researcher
Conducted independent security research via bug bounty programs and identified critical client-side flaws in Jira Cloud and Confluence Cloud that enabled account compromise due to improper user output encoding. Reported findings and supported remediation efforts to reduce risk of unauthorized access to affected parties.
Security Researcher
Discovered a critical logic flaw in a subsidiary (Memorable) that could allow malicious actors to delete entire organization accounts and associated data via unauthorized API requests. Reported through HackerOne and collaborated on remediation to enforce RBAC and require confirmations for destructive actions.
Education
Degrees, certifications, and relevant coursework
Maasai Mara University
Bachelor of Science, Computer Science
Completed a BSc in Computer Science at Maasai Mara University.
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Portfolio
github.com/dennismziaJob categories
Skills
Interested in hiring Dennis?
You can contact Dennis and 90k+ other talented remote workers on Himalayas.
Message DennisFind your dream job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
