Security is not an afterthought; it’s integral to robust development. Justin Riddiough offers web security services grounded in his real-world vulnerability discovery and a commitment to secure coding practices. With his proven success in identifying and reporting security flaws through programs like the Stanford Bug Bounty (~$1500 awarded) and contributions to platforms like HackerOne ($500 awarded), he brings a proactive, attacker-minded perspective to securing your web assets. His focus is on integrating security throughout the Software Development Lifecycle (SDLC).
- Value Delivered: Enhance your security posture with insights derived from Justin’s practical vulnerability research. Protect your digital assets, build user trust, and reduce the risk of breaches by partnering with experience he has validated by recognized security programs.
Let's discuss how this service can help achieve your specific goals.
Schedule ConsultationNeed ongoing security support?
Learn About Subscriptions- Vulnerability Assessment & Reporting: Demonstrated ability to identify and responsibly disclose security vulnerabilities (cross-site scripting, insecure object references, etc.) through formal bug bounty programs.
- Secure Development Lifecycle (SDLC): Applying security principles throughout requirements, design, implementation, testing, and deployment phases.
- Risk Identification & Mitigation: Analyzing potential threats and proposing effective countermeasures based on found vulnerabilities.
- Ethical Hacking Mindset: Approaching security from an adversarial perspective to uncover weaknesses before malicious actors do.
Showcasing specific contributions related to Web Security & Ethical Hacking:

Business Logic Errors - HackerOne Reward
Contribution to Web Security Ethical Hacking:
Identified and responsibly disclosed a security vulnerability (Flaw In Business Logic) via the HackerOne platform, contributing to improved security posture and receiving a $500 bounty.
- Conducted responsible disclosure according to HackerOne’s security policy.
- Provided detailed steps to reproduce the identified vulnerability.
- Collaborated with the security team during the remediation process.
- Received acknowledgement and a $500 bounty reward for the finding.

Stanford Graduate School of Business - Web Development & Security
Contribution to Web Security Ethical Hacking:
Actively participated in Stanford’s Bug Bounty program, identifying and reporting multiple vulnerabilities.
- Identified and reported several vulnerabilities through the Stanford Bug Bounty program (~$1500 awarded).
- Contributed to enhancing organizational security posture through proactive testing.
Custom Web Application Development:
Performed extensive custom Drupal development, supported major migrations, and collaborated on feature implementation like ‘Voices’.
- Developed custom Drupal modules, themes, and distributions (PHP, Drupal APIs).
- Supported migration from Drupal 7 to Drupal 9 (Salesforce integration, content type migration).
- Partnered with marketing on site redesign and ‘Voices’ functionality.
- Refactored code for improved responsiveness and applied caching strategies.
- Worked effectively with release engineers and frontend developers.
- Maintained Linux development build and onboarded colleagues/contractors.