Roger Meyer

Penetration Tester

San Jose, California, United States
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts

Summary

🤩
Rockstar
🎓
Top School
Roger Meyer is a seasoned penetration tester and security engineer based in San Jose with 20+ years in information security and seven years in focused professional roles, blending hands-on testing with leadership experience. He has deep expertise in network, web, mobile, and native application security as well as threat modeling and security architecture, and has progressed from hands-on engineering to technical director roles at NCC Group. Roger co-authored the notable DNS rebinding framework Singularity of Origin and contributed payloads and UX improvements targeting high-impact services like Jenkins, Docker API, and H2 (including CVE-related work). He brings practical protocol-level insight—evident in his CSRF/token mitigations and attention to Rails security nuances—alongside a track record of turning research into exploitable proofs and remediation guidance. Comfortable operating at both red-team depth and advisory breadth, he pairs offensive creativity with pragmatic risk communication for enterprise clients.
code7 years of coding experience
job18 years of employment as a software developer
bookBachelor of Science, Bachelor of Science at School of Engineering and Information Technology Biel
bookMaster of Science, Master of Science at California State University Sacramento
github-logo-circle

Github Skills (14)

it-security10
vulnerabilities10
exploit10
dos-attack10
vulnerability10
security10
javascript9
html9
jenkins-ci8
docker8
jenkins8
dockers8
h2-database7
iot6

Programming languages (3)

JavaJavaScriptHTML

Github contributions (5)

github-logo-circle
nccgroup/singularity

Nov 2018 - Feb 2022

A DNS rebinding attack framework.
Role in this project:
userSecurity Engineer
Contributions:18 commits, 2 PRs, 19 pushes in 3 years 3 months
Contributions summary:Roger focused on enhancing the DNS rebinding attack framework by introducing and refining payloads for various services. They implemented payloads targeting Jenkins Script Console, Docker API, and H2 database (CVE-2021-42392). Their work involved modifying existing code, adding new features, and improving the user interface with added tooltips. The user also addressed security considerations, such as adding CSRF token support and noting the security implications of Ruby on Rails 6.0.
dnsdns-rebindingvulnerabilityattackiot
nccgroup/HTTPSignatures

Dec 2020 - Aug 2022

A Burp Suite extension implementing the Signing HTTP Messages draft-ietf-httpbis-message-signatures-01 draft.
Contributions:2 releases, 5 commits, 1 PR in 1 year 8 months
burpsignatures
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.
Request Free Trial