// resume

Product Security Research

Industrial and AI infrastructure research, open-source security, and security and compliance engineering.

IEVGEN BONDARENKO

PRODUCT SECURITY RESEARCH | INDUSTRIAL & AI INFRASTRUCTURE | SECURITY & COMPLIANCE ENGINEERING

Sacramento, California | Remote | U.S. Citizen[email protected]ibondarenko.comgithub.com/ibondarenko1LinkedIn

PROFILE

Product security researcher working across AI infrastructure, open-source software, robotics, IoT, and industrial systems. Focused on source-led vulnerability research, reproducible validation, root-cause analysis, coordinated disclosure, and remediation verification.

Published and coordinated research includes CVE/GHSA findings in MLflow, Eclipse Ankaios, vLLM, and LMDeploy, plus rewarded Google Cloud VRP research. Current industrial and IoT research includes multi-vendor vulnerability work coordinated through vendor security teams and CISA VINCE.

SELECTED SECURITY RESEARCH

  • MLflow — CVE-2026-64849 / GHSA-7gwp-5pfp-969j

    Credited finder of a Critical unauthenticated SSRF affecting webhook delivery through redirect and DNS-rebinding weaknesses. Reproduced the trust-boundary failure and validated remediation.

  • Eclipse Ankaios — CVE-2026-84173 / GHSA-rp6v-x3q5-cp2g

    Reporter of an authorization flaw allowing scoped workloads to access or modify cluster state outside their intended subtree. Validated the maintainer fix and fixed release.

  • vLLM / LMDeploy

    Reporter for CVE-2026-73560 and CVE-2026-46517, covering multimodal SSRF/local-file boundary bypass and unsafe remote-code trust during model initialization.

  • Google Cloud VRP

    Identified SSRF, Google API-key disclosure, and response forgery through a provider endpoint override in Google Genkit. Report triaged and rewarded by Google Cloud VRP.

  • Industrial / IoT Research

    Active multi-vendor research across device-management software, firmware, network services, certificate validation, protocols, and device-to-cloud trust boundaries. Findings are moving through coordinated vendor and CISA VINCE disclosure processes.

  • Open-Source Security Engineering

    20+ merged upstream security and hardening changes across gVisor, Kubernetes, vLLM, Microsoft Sentinel, Swift Package Manager, OSV-Scanner, Tink, and Google Bumble.

EXPERIENCE

Independent Security Researcher

California, Remote2026–Present

Source-led vulnerability research across AI infrastructure, open-source software, robotics, IoT, and industrial systems. Build reproducible test environments, validate impact, coordinate disclosure, review patches, and retest remediation.

Security & Compliance Consultant

California, Remote2025–Present

Security and compliance assessments across cloud, identity, endpoint, application, and infrastructure environments. Work includes SOC 2, ISO 27001, HIPAA, NIST-aligned controls, technical remediation, and audit readiness.

Computer Security Manager

Technohome Inc. | Roseville, CA2022–2025

Managed Windows/Linux security, hardening, patching, access reviews, network segmentation, pfSense controls, event investigation, and incident-response procedures.

Earlier Career: Business Ownership & Operations Leadership

Founded and operated a U.S. logistics business coordinating several dozen trucks and approximately 50 outsourced personnel.

CORE CAPABILITIES

Vulnerability Research
secure code review, source-to-sink tracing, reverse engineering, firmware/protocol analysis, threat modeling, SAST/DAST/SCA, PoC validation, fuzzing, CWE/CVSS, coordinated disclosure, remediation verification
Product & Infrastructure Security
AI model serving, distributed systems, robotics, IoT, embedded and industrial systems, Kubernetes, containers, authorization, SSRF, TLS/certificate validation, parsers, protocols, supply-chain trust
Detection & Security Engineering
Microsoft Sentinel, Defender XDR, KQL, Sigma, MITRE ATT&CK, Security Onion, Suricata, Zeek, Wazuh, Detection-as-Code
Tools
Python, Go, C++ analysis, Bash, PowerShell, Linux, Docker, GitHub Actions, Semgrep, Joern, CodeQL

CERTIFICATIONS & EDUCATION

  • CompTIA Security+ ce
  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • Sierra College, IT & Cybersecurity, 2025–Present
  • National Metallurgical Academy of Ukraine, B.S. Engineering