Independent Security Researcher
Current• Independent bug bounty research / sabbatical study period during temporary return to Scotland.
Please complete the CAPTCHA to continue
A concise factual answer block for searchers comparing this professional profile.
Michael Arnold is listed as Independent Security Researcher at Independent Consultant, based in Burnaby, British Columbia, Canada. AeroLeads shows a matched LinkedIn profile for Michael Arnold.
Michael Arnold previously worked as Senior Application Security Engineer at Zynga and Senior Security Consultant at Mandiant. Michael Arnold holds Hnd, Computer Software Engineering from Stevenson College, Edinburgh.
This section adds company-level context without repeating Michael Arnold's masked contact details.
Review company-level records connected to Michael Arnold before choosing the right outreach path.
-------• Web AppSec: Comprehensive security assessments of web applications, APIs and supporting infrastructure. Including, but not limited to: ◦ White/black/grey box penetration testing activities, (manual and automated) against the OWASP Top 10, ASVS, biz logic and env config. ◦ Testing RESTful, GraphQL, APIs etc. ◦ Familiarity with file formats such as ProtoBuf, JSON, XML, XML & YAML. ◦ Testing Authentication & Authorization using modern auth such as OAuth2.0, SAML, etc. ◦ Extensive use and exp with tools such as integrated browser devtools, Burp Suite Professional, Selenium, Visual Studio, EclipseIDE & cheffing up of custom burp exts as required. -------• Mobile AppSec: Security assessments of cross-platform mobile applications (Android & iOS), APIs, supporting network/cloud infrastructure and reverse engineering apps.-------• Thick AppSec: Security assessments of cross-platform thick/enterprise applications (Windows & Linux): ◦ Leveraging of transparent layer 3 network proxies for system wide, full protocol interception & analysis capabilities. ◦ Performing DBI augmented reverse engineering and debugging using Frida and other decompilation/debugging tools.-------• AppSec Engineering: Safeguarding games/apps from cyber attacks, encompassing both "shift-left" SDLC security integration & hands-on technical application pen-testing, Involving but not limited to: ◦ Extensive usage/familiarity with OOP languages C#/.Net Core/ASP.NET Core, Python, PHP, Java, JavaScript/Node.js & CodeQL. ◦ Threat Modeling/Risk Assessment: Analysis of large system design architecture, data flow and user interactions to assess attack vectors/vulns. ◦ Shift Left SDLC: Integrating security measures early in the SDLC. ◦ SAST/DAST Integration: CodeQL powered manual/auto white box source code review, DBI assisted AFL Fuzzing, traffic analysis etc.-------• Red Team Ops | Adversary Simulation: Engaged in RTO simulation of APT threats to emulate real-world cyber attacks; including: ◦ Design/exec of complex, multi-stage RTO engagements tailored to org envs. ◦ Employing a wide range of attack TTPs to simulate real-world attacker behaviors/methodologies. ◦ Adapting/evolving strategies based on the target env, defensive mechanisms, and emerging threats. ◦ Development of custom tools. ◦ Delivery of comprehensive and actionable reports.-------• CloudSec: Safeguarding cloud infrastructure from cyber attacks, including but not limited to Cloud: ◦ Risk Assessment. ◦ Identity and Access Management (IAM). ◦ Security Best Practices.
Company context helps verify the profile and gives searchers a useful next step.
A career timeline built from the work history available for this profile.
London, Gb
• Independent bug bounty research / sabbatical study period during temporary return to Scotland.
San Francisco, California, Us
Technical security assessments including:• Penetration testing of cross-platform mobile applications (iOS/Android), thick client applications (desktop), web services, & Cloud front-end & back-end services.• Validation of internal, external and crowd-sourced application security vulnerabilities and articulation of issue/remediation steps to the relevant engineering teams.• Maintain and augment security engineering infrastructure services and custom tooling used by the application security team.• Reverse engineering of mobile application products and source code reviews (manual and SAST code audits).• Documentation of game architecture and performing threat modeling for white-box assessment activities.• Evaluation of product security and security architecture from an offensive and defensive mindset.• SME for secure coding practices, penetration testing, mobile platform security and all aspects of application and product security.
Mountain View, California, Us
Technical security assessments and ethical hacking engagements, including:• Penetration Testing• Red Teaming• Network Vulnerability Assessments• Web Application Security Assessments• Social Engineering• Audits• Software Vulnerability Research
Kansas City, Mo, Us
Technical security assessments and ethical hacking engagements, including:• Penetration Testing• Network Vulnerability Assessments• Web Application Security Assessments• Social Engineering• Firewall Rule Review• Network Security Architecture Review• Audits• Software Vulnerability Research
• Review requirements, architecture & design documentation to verify that servers are being provisioned in the correct network zones.• Implement firewall changes.• Troubleshoot firewall/network connectivity issues.• Perform vulnerability assessments and remediation.• Implement Active Directory & DNS changes as required.• Troubleshoot Active Directory and Kerberos related issues.
Burnaby, Bc, Ca
• Performed non-automated, application security assessments on province wide web applications prior to being exposed externally.• Coordinated application/server migrations to a Tier 3 Data Center.• Identified application firewall requirements using specific network monitoring tools as well as manual/scripted data parsing.• Worked with Virtual, Networking, Security and Windows teams to ensure migrations and net new builds were met as per specification.
Vancouver, British Columbia, Ca
Break/fix desktop support, domain migration.
Edinburgh, Scotland, Gb
• Provided IT support for ~250 sites across Scotland.• Designed and implemented hub-spoke architecture and Active Directory consolidation/upgrade to 2008 single domain.
Provided IT support and installations for numerous clients across the central belt.
Quick answers generated from the profile data available on this page.
Michael Arnold works for Independent Consultant.
Michael Arnold is listed as Independent Security Researcher at Independent Consultant.
Michael Arnold is based in Burnaby, British Columbia, Canada while working with Independent Consultant.
Michael Arnold has worked for Independent Consultant, Zynga, Mandiant, Herjavec Group, and Bc Clinical And Support Services Society (Bccss).
You can use AeroLeads to view verified contact signals for Michael Arnold at Independent Consultant, including work email, phone, and LinkedIn data when available.
Michael Arnold holds Hnd, Computer Software Engineering from Stevenson College, Edinburgh.
Search by job title, company, industry, location, and seniority. Export verified B2B contact data when you need it.
Start free trial Search contacts