Kenji Subagja
I break backend systems for a living — auth flows, APIs, access control — then write it up properly for the team that has to fix it. Off the clock, I'm building the same kind of systems I spend my day trying to break.
I build backend systems, then try to break them.
I started as a backend developer — APIs, databases, auth, the plumbing most people never see. Building that plumbing made me curious about exactly where it cracks, which is what pulled me into bug bounty.
Those two things run in parallel now. When I'm shipping a feature, I think about how I'd attack it. When I'm testing someone else's system, I think about the engineer who has to patch it by tomorrow morning.
I run private and public bug bounty programs, take on backend contracts on the side, and occasionally write up interesting findings once disclosure allows it.
What I actually work with
No frontend frameworks — this is the offensive-and-backend half of the stack.
33 valid reports and counting
Real findings across the bug bounty programs I've tested.
Short version
Freelance Backend Engineer & Security Researcher
2022 — Presentwhile building small tools on contract for individual clients and community use, Taking private bug bounty invites and running public disclosures as a security researcher.
Have a system that needs testing, or a backend that needs building?
Open to private bug bounty programs, security research collaborations, and backend contract work.