Security leader who remains deeply hands-on technically, with 20+ years identifying business-critical vulnerabilities and scaling security programs around that work. Has personally found zero-day-class flaws, systemic misconfigurations, and high-impact weaknesses in every role held, then translated those findings into executive risk decisions, engineering priorities, and durable assessment methodologies. Experienced across offensive security, privacy risk, AI security research, team growth, and cross-functional collaboration with legal, compliance, product, and engineering. (https://sholuv.net/audio/Leons_Resume_Podcast.mp3)
| CVE-2026-28279 | High (8.4) | OS Command Injection in osctrl-admin. Authenticated admin injects shell commands via hostname parameter; commands execute as root/SYSTEM on all enrolling endpoints. Co-discovered with Kwangyun Keum @ TikTok USDS. |
| CVE-2026-28280 | High (8.7) | Stored XSS in osctrl-admin query list. Low-priv user injects persistent JavaScript; chainable with CSRF for privilege escalation and full platform compromise. Co-discovered with Kwangyun Keum @ TikTok USDS. |
28+ conference talks, panels, and media appearances on offensive security, social engineering, AI risk, and supply chain security. Venues include RSA Conference, BSides, Rapid7 UNITED Summit, Forrester Forums, and podcasts (Layer 8, Security Ledger). Full list at sholuv.net/work.html