Johan Carlsson is a security researcher and full-time bug bounty hunter from Gothenburg, Sweden, with eight years of hands-on software and security experience. He spends much of his time hunting vulnerabilities in platforms like GitLab (HackerOne: joaxcar) and combines application security expertise with a particular interest in web quirks and browser behavior. Johan has moved from system administration into software engineering roles at Recorded Future and Spinit before transitioning to his current role at Götebug AB, bringing practical product-facing development experience to security investigations. He holds a Bachelor's in Computer Science from KTH and wrote his bachelor thesis in cybersecurity, reflecting a formal foundation underpinning his offensive work. An occasional blog writer and active online handle joaxcar, he blends hobbyist curiosity with professional rigor—and often treats obscure browser oddities as mini research projects.
8 years of coding experience
7 years of employment as a software developer
Bachelor's degree Computer Science, Bachelor's degree Computer Science at KTH Royal Institute of Technology
Gymnasiet Teknik: nätverk och programmering, Gymnasiet Teknik: nätverk och programmering at Thorildsplans gymnasium
Bachelor's degree Fine/Studio Arts General, Bachelor's degree Fine/Studio Arts General at Oslo National Academy of the Arts (KHiO)
Contributions:12 pushes, 1 branch in 4 years 4 months
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.