Gareth Heyes — Consultant
I’m a security researcher passionate about breaking the web in creative ways so others can build it back stronger. With over a decade of experience uncovering cutting-edge browser exploits, bypasses, and XSS techniques, I’ve helped shape the field of offensive web security. Currently at PortSwigger, the makers of Burp Suite, I spend my time fuzzing the edge cases of JavaScript, HTML, and browser parsers - often discovering new ways to weaponise overlooked features. I’m the author of JavaScript for Hackers, a practical guide to thinking like an attacker and exploiting real-world web apps using advanced JavaScript payloads and techniques. My work has influenced security tools, WAF evasions, CSP research, and continues to push the boundaries of what’s possible in modern web attacks.
Stackforce AI infers this person is a Cybersecurity expert specializing in web application security and vulnerability research.
Location: Blackburn, United Kingdom
Experience: 27 yrs 8 mos
Skills
- Web Application Security
- Security Research
- Web Development
Career Highlights
- Over a decade of experience in offensive web security.
- Authored 'JavaScript for Hackers', influencing security practices.
- Developed tools enhancing Burp Suite's detection capabilities.
Work Experience
PortSwigger Web Security
Researcher (11 yrs 1 mo)
Cloud1990
Software Developer (11 mos)
Fairpoint
Senior Web Developer (4 mos)
Microsoft
Independent Security Researcher (4 yrs 10 mos)
Ignition NBS Ltd
Senior web developer (5 yrs 6 mos)
Hilden Design
Senior web developer (1 yr)
Interactive2K/Netsmart
Senior Web developer (2 yrs)
Subnet new media
Web developer (2 yrs)
Education
at Pleckgate High School