Available for consulting engagements

Florian Bidabé

Cyber Security Leader & Researcher

15+ years in IT and cybersecurity. Strategy & Innovation Lead at Commonwealth Bank. Bug bounty researcher with findings at GitHub, Microsoft, Atlassian, and Wiz. Founder of PhotonSec.

15+
Years Experience
6+
Bug Bounty Findings
4
Major Employers
20+
Technical Articles
Scroll

Expertise

What I Do

A decade of experience across the full security spectrum — from hands-on offensive work to strategic consulting.

Offensive Security

Penetration testing, red team operations, web application assessments, API security, and bug bounty research targeting major tech platforms.

PentestingRed TeamBug BountyWeb App Security

Cloud Security

Azure and Microsoft 365 security architecture, Entra ID hardening, Conditional Access design, and cloud-native threat detection.

AzureM365Entra IDZero Trust

Infrastructure Hardening

Enterprise security baselines, network segmentation, endpoint hardening, and security automation for large-scale environments.

HardeningAutomationBaselinesCompliance

AI/LLM Security

Security assessment of AI/LLM systems, prompt injection research, OWASP LLM Top 10, and threat modelling for AI-integrated applications.

LLM SecurityPrompt InjectionAI Threat Modelling

Security Tooling

Building open-source security tools, automation frameworks, and custom tooling for security workflows in Python, TypeScript, and PowerShell.

PythonTypeScriptOpen SourceAutomation

Consulting & Leadership

Security strategy, architecture advisory, technical leadership, and executive-level security guidance for organisations and security teams.

StrategyAdvisoryLeadershipArchitecture

Responsible Disclosure

Bug Bounty Findings

Vulnerabilities responsibly disclosed to major technology companies.

6+
Vulnerabilities Reported
4
Companies Affected
100%
Responsibly Disclosed
3
High/Critical Severity
High
GitHub · 2024

Data Exposure

Identified a security flaw allowing unauthorised access to sensitive repository data, reported to GitHub Security.

Full write-up in Member Zone
Medium
GitHub · 2024

Access Control Bypass

Discovered a bypass mechanism in GitHub Copilot's access controls, enabling unauthorised feature access.

Full write-up in Member Zone
Medium
GitHub · 2024

Business Logic Flaw

Found a business logic vulnerability allowing bypassing of Copilot subscription pricing controls.

Full write-up in Member Zone

Work With Me

Need a Security Expert?

Whether you need a penetration test, cloud security review, security architecture guidance, or AI/LLM threat assessment — let's talk.