Soroush Dalili — Product Manager
Security researcher with over 20 years of experience in vulnerability research, exploit development, and offensive tooling. Discovered the IIS Short File Name Disclosure vulnerability, maintain the YSoSerial.Net deserialization framework, and have contributed security advisories to Microsoft, Mozilla, Adobe, Yahoo, and Facebook. Speaker at AppSec EU, SteelCon, and NDC Manchester. Now applying AI-assisted techniques to security research, including building security tools with LLM coding agents (Claude Code, GitHub Copilot, Codex), developing AI-augmented source code auditing workflows, and researching AI-enabled vulnerability discovery and exploit development.
Stackforce AI infers this person is a Cybersecurity expert specializing in vulnerability research and application security.
Location: Worcestershire, England, United Kingdom
Experience: 20 yrs 1 mo
Skills
- Application Security
- Cybersecurity
- Vulnerability Assessment
- Penetration Testing
- Vulnerability Research
- Web Application Security
Career Highlights
- Over 20 years of experience in security research.
- Pioneered AI-assisted security auditing workflows.
- Contributed security advisories to major tech companies.
Work Experience
Bentley Systems
Principal Application Security Engineer (7 mos)
SecProject Ltd
Director (3 yrs)
MDSec
Principal Research Consultant (3 yrs 5 mos)
NCC Group
Principal Security Consultant (2 yrs 4 mos)
Managing Security Consultant (1 yr 5 mos)
Senior Security Consultant (1 yr 10 mos)
Bet365
Senior Information Security Specialist (4 yrs)
Meal2Go ltd
Security Adviser (part time contracting) (4 mos)
Contracting
Web Application Security Tester (part time contracting) (2 yrs 4 mos)
Pars IT Net
Web Developer (part time contracting) (1 yr 5 mos)
Education
MSc. at University of Birmingham
BSc. at Shahid Beheshti University