Jason Haddix

CEO

Aurora, Colorado, United States18 yrs 11 mos experience
Highly Stable

Key Highlights

  • Led global cybersecurity efforts for over 20,000 employees.
  • Expert in penetration testing and vulnerability management.
  • Regular speaker at top security conferences worldwide.
Stackforce AI infers this person is a Cybersecurity expert with extensive experience in consulting and security management.

Contact

Skills

Core Skills

CybersecurityConsultingSecurity ManagementRisk ManagementVulnerability AssessmentApplication SecurityPenetration TestingSecurity ConsultingSecurity Research

Other Skills

Cybersecurity ConsultingTrainingCorporate SecurityInfrastructure SecurityVulnerability ManagementSecurity OperationsMethodology DevelopmentNetwork Penetration TestingWeb Application TestingSecurity Process DevelopmentCrowdsourced Security TestingBug Bounty ProgramsOnline JournalismMethodology ImplementationMobile Applications

About

I previously served as the Head of Global Cyber Security for Ubisoft, where I led all efforts in information security. My group protected over 20,000 employees worldwide with a vast scope (see job desc for more) In my previous roles such as Director of Penetration Testing, I led efforts on matters of information security consulting. The gamut stretched from developing penetration testing plans for Fortune 100 companies to competing in "bake-offs" to win business against other top-tier consulting vendors. I have also served as a Director of Operations, leading teams of highly technical Application Security Engineers and Technical Operations staff. In this role, I was an extension of (and advisor to) over 300+ security programs across many industry verticals. Under my direction, my team triaged over 22,000 vulnerabilities in 2018-2019 alone. Personally, I love being in the trenches and performing actual assessments, but I am also adept at handling clients, architecting solutions, designing services, improving business processes, managing technical consultants, training, technical writing, marketing, and delivering solutions. While my strengths are web, network/infrastructural, and mobile security, I have personally performed a myriad of other services and implemented them for a consultancy as a deliverable (mainframe, wireless, cloud assessment, database, OSINT, APT simulation, binary reversing, and static code analysis). In my free time, I write for several information security publications and am a semi-regular capture-the-flag player. I speak regularly at security conferences globally (DEFCON, Blackhat, OWASP, and many more) While I never call myself a "master" of anything, I do have a very particular set of skills; skills I have acquired over a very long career. These skills make me adept at helping businesses, finding security vulnerabilities, and leading a business to a better security posture.

Experience

Bugcrowd

Strategic Advisor (Part Time)

Apr 2024Jan 2025 · 9 mos · Remote

Flare

Field Chief Information Security Officer (Part Time)

Feb 2024Nov 2025 · 1 yr 9 mos · Remote

Arcanum information security

CEO & Hacker & Trainer

Jan 2024Present · 2 yrs 3 mos · United States · Remote

  • I am the Founder, CEO, hacker, and trainer for Arcanum Information Security. We offer high tier cybersecurity consulting services and training.
Cybersecurity ConsultingTrainingCybersecurityConsulting

Buddobot

Chief Information Security Officer

Jan 2023Dec 2023 · 11 mos

Ubisoft

Head of Security and Risk Management

Jul 2019Jan 2023 · 3 yrs 6 mos · San Francisco Bay Area

  • Led and managed a global security team tackling:
  • Corporate Security: privacy, compliance, physical security, security awareness, business continuity, disaster recovery, crisis management, identity, fraud, and access management.
  • Application and Infrastructure Security: red team, bug bounty, incident response, threat hunting, security architecture (cloud, enterprise, devsecops, web services)
  • Game Security: production assistance, cheat testing, game security assessment, anti-piracy, anti-cheat.
Corporate SecurityApplication SecurityInfrastructure SecuritySecurity ManagementRisk Management

Bugcrowd inc

5 roles

VP of Researcher Growth

Oct 2018Jun 2019 · 8 mos

VP of Trust and Security

Jan 2018Oct 2018 · 9 mos

  • As VP of Trust and Security, I provide leadership and guidance to Bugcrowd and it's customers relating to creating and sustaining high impact crowd-sourced security solutions (bug bounties and disclosure programs). On top of this, I manage a group of Security Engineers and Bug Hunters that leads special projects as well as does all Sales Engineering for Bugcrowd. In 2017 we tackled problems like matching crowds to complex technology stacks, remediation advice, target discovery technology, improved researcher tooling (presented at DEFCON 25), an Improved RFP process, and managing the incoming RFE process for the business. In 2018 our goals are to focus primarily on researcher enablement.

Head of Trust and Security

Promoted

Sep 2016Jan 2018 · 1 yr 4 mos

  • Dedicated to providing value to the global security market and the global security researcher community.
  • I am responsible for providing leadership, strategic guidance, and operational guidelines to Bugcrowd and its clients. I am focused primarily on internal and external security policies, customer enablement, researcher engagement, and edge-case program management. I work with clients and security researchers to create high value, sustainable, and impactful bug bounty and responsible disclosure programs.

Director of Technical Operations

Promoted

May 2015Sep 2016 · 1 yr 4 mos

  • Responsible for managing and training internal analysts. We curate, triage, and validate vulnerability data from over 16,000 researchers including (but not limited to) hardcore vulnerabilities in mobile, web, and IoT applications/devices. We bring this data to enterprise clients to help bolster security operations programs. I also work with Bugcrowd to improve the security industries relations with researchers and work closely with sales, customer success, researcher operations, and marketing.
Vulnerability ManagementSecurity OperationsVulnerability AssessmentSecurity Management

Security Researcher, Leaderboard Position #1

Mar 2014Oct 2014 · 7 mos

  • Bugcrowd is a crowdsourced security testing platform allowing security researchers to register and participate in security bug bounties. They retain up to 30,700 registered testers and gamify their results by keeping up a "leaderboard". This leaderboard is climbed by finding web and mobile vulnerabilities in bug bounty programs.
  • Every year they recognize the top researcher in that "number one" position during the Blackhat and Defcon Security conferences. In 2014 I earned that title by occupying the #1 position.
Penetration TestingSecurity Process DevelopmentSecurity ConsultingApplication Security

Hp fortify

2 roles

Director of Penetration Testing

Promoted

Nov 2011May 2015 · 3 yrs 6 mos

  • At HP/Fortify I design methodologies and solutions to the toughest application security problems. Current projects include creating a binary analysis engine for iOS and Android applications, creating a security based asset discovery tool, interviewing/training mobile auditors, and maintaining the web/mobile/binary testing methodologies with cutting edge methods. This is on top of continued application assessments for iOS/Android/web applications and client interactions/pitches.
  • I am also in charge of the following Penetration Testing processes:
  • Methodology Development
  • Mobile Application Testing
  • Infrastructure Testing
  • Web Application Testing
  • Social Engineering Testing
  • Vulnerability Assessment
  • Security Research
  • Process Development
  • Customer Interaction
  • Engineer Training and Development
  • Marketing and Industry Presence
Methodology DevelopmentPenetration TestingApplication Security

Sr Security Consultant (Professional Services)

Sep 2010Nov 2011 · 1 yr 2 mos

  • As a Sr Consultant I was counted on to deliver high quality assessments under the HP name to approximately 25% of the Fortune Top 100 list (2012 Rankings) and follow up with concise recommendations for security and application remediation.
  • I was also involved at the Sr level in the following:
  • Network Penetration Tests and Assessments
  • Web Application Penetration Testing and Assessments
  • Mobile Application Penetration Testing and Assessments
  • Thick/Binary Application Penetration Testing and Assessments
  • Security Process Development
  • Methodology Development
  • Infosec Journalist and Evangelism
  • RFP Responses
  • Service Offering Development
  • Environment building
Network Penetration TestingWeb Application TestingSecurity ConsultingApplication Security

Redspin, inc

Sr. Security Engineer / Lead Penetration Tester

Aug 2009Sep 2010 · 1 yr 1 mo

  • At Redspin I worked as Sr Engineer augmenting many of the already stellar audit methodologies with new penetration testing modules. I worked closely with other Sr staff to create the web assessment methodology. I also handled the following:
  • Large Scale External Penetration Tests and Assessments
  • Web Application Penetration Testing and Assessments
  • Social Engineering Assessments
  • Security Process Development
  • Tool Development
  • Infosec Journalist and Evangelism
  • RFP Responses
  • Service Offering Development
  • Pre-Sales calls
Crowdsourced Security TestingBug Bounty ProgramsSecurity ResearchVulnerability Assessment

Citrix online

IT Generalist

Mar 2007Aug 2009 · 2 yrs 5 mos

  • At Citrix I provided general IT Support to the internal organization. I also worked with development and identified security issues in internal web applications (XSS, session, SQLi, etc).
Penetration TestingSecurity Process DevelopmentSecurity ConsultingApplication Security

Stackforce found 100+ more professionals with Cybersecurity & Consulting

Explore similar profiles based on matching skills and experience