Rand Deeb

A developer’s understanding. A researcher’s scrutiny.

I’m Rand Deeb, a lead software engineer and independent security researcher. I develop systems, applications, websites and portfolios—from a personal site to a complex business platform. My security work includes vulnerability research and custom SAST and DAST tools.

Software engineering meets information-security research.

I hold a bachelor’s degree in Software Engineering and have completed doctoral studies (aspirantura) in Information Security in Russia. I passed the university defense; the final dissertation defense is pending. This background connects how systems are designed and built with research into how they can fail. I apply both perspectives to architecture, vulnerability discovery and remediation.

My full-stack development background helps me understand how a feature is built and how a fix will affect the rest of the application. I combine that perspective with security testing, code review and vulnerability research.

I also design and develop advanced security applications for static analysis (SAST) and dynamic testing (DAST). This work connects software architecture, detection logic and reproducible evaluation—experience I can apply to a scoped tool development or extension project.

At Confident, my engineering work spans SAST, DAST, C++ and security engineering. Previously, I worked in web development and web security at Momento.

My security research has received seven acknowledgments from Meta for Facebook and Instagram findings. In Linux kernel code, I have investigated more than 300 review reports and findings through static analysis and contributed eight patches. My work also includes two published CVEs, CVE-2024-26855 and CVE-2025-37858, with fixes accepted into mainline Linux. The ice driver fix was backported to stable trees. The CVE records and linked fixes are available for you to inspect.

Hendra is a concrete example: a modular, context-aware DAST scanner I developed during my completed doctoral research project at ITMO University. I designed its core architecture and the components for technology identification, scan planning, request deduplication, finding review and benchmarking. My publications examine the methods behind this work.

For your project, the goal is practical: understand the relevant weaknesses, explain the cause and give your team evidence and guidance it can act on.

01Expertise you can verify

International recognition. Hands-on security research.

Acknowledged by Meta. Linux kernel research spanning static analysis, patches and published CVEs. I bring that investigative experience to your code, your product and the fixes your team needs.

7

Acknowledgments from Meta’s security team

Meta Whitehat

300+

Linux kernel findings investigated through static analysis

Code review experience

8

Linux kernel patches

Kernel contributions

2

Published Linux kernel CVEs

Explore the CVE research
Rand Deeb speaking at ISP RAS Open 2024 in Moscow, holding a microphone in front of a blue conference screen

Conference speaker · ISP RAS Open 2024

Research presented in Moscow.

At ISP RAS Open 2024, I presented my research on using machine learning to predict web-stack technologies beyond traditional fingerprints. My talk is listed in the official conference programme.

Predicting web-stack technologies with machine learning: beyond traditional fingerprints

A practical question behind application testing: what is the software actually built with?

View the conference programme

05About

Engineering & security experience

  1. 2023 — Present

    Lead Application Security Engineer

    Confident · ООО «Конфидент»

    Secure code review, vulnerability validation and security engineering across SAST, DAST, C++ and SIEM.

  2. 2020 — Present

    Independent security researcher

    Meta Bug Bounty · Bugcrowd

  3. 2018 — 2019

    Web development & web security manager

    Momento

  4. SAST → DAST

    Bachelor’s project on SAST · Master’s on DAST · Completed doctoral research at ITMO University

    ITMO University

08Contact

Let’s solve the next hard problem.

Tell me what you’re building, what is at stake and when you need a result. I’ll discuss the fit and propose a defined scope, deliverables and price.