
#49 He Found Vulnerabilities in His Own Code: Then Made a Career Out of It ft. John Kounelis
About this episode
In this episode of The Hacker’s Cache, Kyser Clark interviews John Kounelis, a Senior Product Security Engineer with a background in software development and AppSec. John shares how discovering vulnerabilities in his own code led him to a full-time role in application security, and explains the key differences in AppSec across defense, biotech, and SaaS industries. They discuss the realities of bug bounty hunting, the limitations of CTFs, how developers unintentionally introduce vulnerabilities, and why understanding vulnerability chaining is critical for advanced web app testing. Whether you're transitioning from development to security or looking to sharpen your real-world pentesting skills, this episode delivers practical insight into what it truly takes to thrive in AppSec.
Connect with John Kounelis on LinkedIn: https://www.linkedin.com/in/john-k-765b42148/
Connect
---------------------------------------------------
https://www.KyserClark.com
https://www.KyserClark.com/Newsletter
https://youtube.com/KyserClark
https://www.linkedin.com/in/KyserClark
https://www.twitter.com/KyserClark
https://www.instagram/KyserClark
https://facebook.com/CyberKyser
https://twitch.tv/KyserClark_Cybersecurity
https://www.tiktok.com/@kyserclark
https://discord.gg/ZPQYdBV9YY
Music by Karl Casey @ White Bat Audio
Attention Listeners: This content is strictly for educational purposes, emphasizing ETHICAL and LEGAL hacking only. I do not, and will NEVER, condone the act of illegally hacking into computer systems and networks for any reason. My goal is to foster cybersecurity awareness and responsible digital behavior. Please behave responsibly and adhere to legal and ethical standards in your use of this information.
Opinions are my own and may not represent the positions of my employer.
Get every episode summarized
Each time The Hacker's Cache publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from The Hacker's Cache

#71 Metasploit Creator: Why CVEs Won’t Save You in 2025 ft. HD Moore
The Hacker's Cache

#70 From Teen Hacker to Professional Pentester: The Journey of Kyle Hoehn
The Hacker's Cache

#69 Why He Left a Safe Job to Hack Companies for a Living ft. Jim Schultz
The Hacker's Cache

#68 Q&A: Why You’ll Fail in Cybersecurity if You Stop Learning
The Hacker's Cache