Category 02
Offensive Security
Pentesters, red team operators, vulnerability researchers, exploit developers who find the weaknesses before the adversaries do.
Who should apply
- Penetration testers finding critical vulnerabilities before attackers
- Red team operators simulating advanced persistent threats
- Vulnerability researchers discovering CVEs in popular software
- Exploit developers building proof-of-concept tools
- Bug bounty hunters with consistent high-severity findings
What judges look for
- Critical or high-severity vulnerabilities discovered with real-world impact
- Novel attack techniques or bypass methods developed
- Responsible disclosure process that improved vendor security
- Red team engagements that changed how an organization defends
- Open-source security tools or research shared with the community
Eligibility
Universal criteria
Experience & leadership
3โ5+ years in technology, mid-tier (non-CXO) roles, proven leadership and impact.
Innovation & creativity
Demonstrated problem-solving and creative solutions within your field.
Growth & mentorship
Continuous learning plus developing others through mentorship or training.
Adaptability & resilience
Proven resilience through crises or significant organizational change.
Ethics & responsibility
High ethical standards, diversity & inclusion, community and sustainability work.
Candidates
Nominees in Offensive Security
Common questions
FAQ
Can I apply if my work is classified?
Yes. You can describe methodology and impact without revealing client details or specific targets.
Does bug bounty work count?
Yes. Consistent high-severity findings on platforms like HackerOne or Bugcrowd demonstrate real skill.
Know someone who deserves this?
Urge them to apply or nominate someone you know
Help us find the best talent. Apply yourself or nominate a colleague โ every great candidate starts with someone who believes in them.
Share this category and help us discover more amazing candidates.
