The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/WE'RE IN!
WE'RE IN! artwork

Becoming a Level 5 Researcher in Just 3 months with Austin, Synack Red Team

WE'RE IN! · 2026-06-15 · 16 min

0:00--:--

Key moments - from our scoring

Substance score

27 / 100

Five dimensions, 20 points each

Insight Density5 / 20
Originality4 / 20
Guest Caliber5 / 20
Specificity & Evidence7 / 20
Conversational Craft6 / 20

Austin's rapid ascent to Level 5 on the Synack Red Team in just three and a half months stands out against peers who take years to reach the same rank. As a full-time security consultant conducting penetration tests daily, Austin brings professional experience to his Synack work, focusing on authorization flaws and injection vulnerabilities rather than low-hanging fruit like CAPTCHA bypasses. His breakthrough came after initial denial - he pursued his OSCP certification and reapplied successfully, a turning point he emphasizes repeatedly. Austin compares Synack favorably to open platforms like HackerOne and BugCrowd, citing faster triage times (he had SQL injection reports triaged within 24 hours), smaller competition pools (300 versus 10,000 hunters), and access to FedRAMP targets restricted to US-based researchers. A standout finding involved compromising an entire financial services dashboard by extracting an admin user ID from a JWT token in a low-privileged user's request. Austin credits mentorship from established Red Team members - Logue, Ferdum, and Insider Threat - as instrumental to his success, and advocates for continuous learning by studying HackerOne hacktivity reports and bug bounty newsletters to apply proven techniques on Synack targets.

Key takeaways

  • →Reaching Level 5 on Synack in 3.5 months is achievable with OSCP certification, mentorship, and specialization in high-value vulnerabilities like authorization and injection flaws rather than low-hanging fruit.
  • →Synack offers faster triage times (24-48 hours versus weeks/months), smaller competition pools (300 hunters versus 10,000), and exclusive FedRAMP targets for US researchers compared to HackerOne and BugCrowd.
  • →Initial rejection from Synack can be overcome by obtaining relevant certifications - Austin's OSCP pursuit after denial directly enabled his successful reapplication.
  • →Studying public bug bounty reports and techniques from HackerOne hacktivity feeds and newsletters can directly improve vulnerability discovery rates and success on Synack targets.
  • →Balancing full-time penetration testing work with Synack hunting is viable and enhances expertise, as real client work translates to better vulnerability identification on Synack targets.

In this episode

  1. 1Introduction to Austin and the Synack Red Team
  2. 2Day-to-Day Vulnerability Research and Target Scope
  3. 3Achieving Level 5 in Three Months
  4. 4Origin Story: From Video Game Mods to Cybersecurity
  5. 5Joining Synack Red Team and Initial Rejection
  6. 6Advantages of Synack Over Public Bug Bounty Platforms
  7. 7Patch Verification Process and Real-World Example
  8. 8Financial Services Case Study: Authorization Vulnerability

Mentioned

SynackSynack Red TeamAustinJosh MasonHackerOneBugCrowdCheat EngineOSCPWikiLeaksFedRAMPEJPTLogue

Guests

Austin

Topics in this episode

SQL injectionHackerOneBugcrowdSynack Red TeamOSCP certificationAuthorization vulnerabilities (IDORs)JWT tokensFedRAMP targetsPatch verificationSecurity consultant

Questions this episode answers

How long did it take Austin to reach Level 5 on Synack Red Team?

Austin reached Level 5 in approximately 3.5 months, which he notes is significantly faster than most Red Team members who take years to achieve that rank.

What certification did Austin pursue after being initially denied to Synack?

After his first denial due to insufficient certifications and experience, Austin immediately pursued and passed his OSCP (Offensive Security Certified Professional) certification before reapplying successfully.

What vulnerabilities does Austin specialize in finding?

Austin specializes in authorization issues (including IDORs) and injection vulnerabilities, particularly SQL injections, deliberately avoiding low-value findings like CAPTCHA bypasses.

How does Synack compare to HackerOne and BugCrowd for bug hunters?

Synack offers faster triage times (24-48 hours versus weeks to months), smaller competition pools (around 300 hunters versus 10,000), and exclusive opportunities like FedRAMP targets for US-based researchers.

What was Austin's notable finding on the financial services platform?

Austin extracted an admin user ID from a JWT token in a low-privileged user's request, which allowed him to compromise the entire financial services dashboard and perform all administrator actions.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

5 / 20

The episode is almost entirely a promotional and recruitment conversation for Synack, with one genuinely interesting technical anecdote (JWT token vulnerability). Generic filler like 'always keep learning' dominates the runtime, and there is nothing a B2B operator couldn't have reasoned out themselves.

Always keep learning. This field constantly changes on a day to day basis.
I would highly recommend getting some certifications

Originality

4 / 20

The content recycles standard cybersecurity career advice and openly promotional comparisons of Synack to public bug bounty platforms. There is no contrarian or first-principles thinking at any point in the episode.

Always keep learning. This field constantly changes on a day to day basis.
I would highly recommend getting some certifications you know not I feel like I was kind of conquering the infinity stones collecting all these certifications

Guest Caliber

5 / 20

Austin is a three-month-old platform member and mid-level security consultant, not a senior operator or practitioner who has driven measurable business outcomes at scale. His technical chops are evident but his seniority and B2B relevance are minimal.

I've been on Sinec Red Team for about three months, three and a half months. So I know other people on your podcast have been here for years and years. So I'm pretty much a newbie
I am a security consultant for a cyber security firm so I do a lot of pen tests daily non-Synac

Specificity & Evidence

7 / 20

The financial services platform JWT token story is a concrete and credible technical example, and a handful of real numbers appear (10,000 vs 300 competitors, FedRAMP scope, three SQL injections triaged in one day). This is above average for a short promotional episode, though no business-impact metrics are provided.

If you inspected your JWT token, inside was your admin user ID. And I used that and was able to compromise the entire platform
instead of going against 10,000 people, you're going against 300 people

Conversational Craft

6 / 20

The host asks a few targeted follow-ups (asking about specialties, patch verification workflow, and what differentiated Austin) but never challenges a claim or pushes beyond the guest's comfort zone. The overall tone is a friendly PR chat and the questions frequently lead to promotional answers.

What's different about you? Have you been pen testing things since you were able to read or what was your hacker origin story?
Is there a favorite target? or not, don't tell me the company or the organization

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

team16synac14back11nice8level8target7different7patch7client6sinec5three5field5security5example5verification5sinek5

Episode notes

In this episode of WE'RE IN , Josh Mason sits down with SRT member Austin, a rising star on the Synack Red Team. Austin shares his hacker origin story and pulls back the curtain on what it takes to break into elite researcher programs. He also deep-dives into his recent "heavy hitter" win: using a JSON Web Token inspection to completely demolish the authorization schema of a U.S. financial services platform, gaining full administrative control. TIMESTAMPS: 00:00 - Introduction 00:39 - A Day in the Life of an SRT Hacker 02:08 - Fast Track to Synack Red Team Level 5 03:12 - Hacker Origin Story 04:40 - Mentorship in Synack Red Team 05:46 - HackerOne vs. Synack: Why Synack is Better for Researchers 07:02 - How Patch Verifications Actually Work 09:16 - Compromising a Financial Platform via JWT 11:10 - Advice to Join the Synack Red Team: Get your OSCP 12:32 - Advice to Cyber Newbies: Always Keep Learning 14:14 - Hunting Authorization and Injection Issues for Synack Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Full transcript

16 min

Transcribed and scored by The B2B Podcast Index.

Hello and welcome to the latest episode of We're In brought to you by Cynac. I'm Josh Mason, Solutions Architect. And with me today is one of our Cynac Red Team members, Austin. Austin, thanks for joining us.

Yeah, no problem, Josh. Thanks for having me. I really appreciate it. Yeah, man.

Austin, you've been on the Cynac Red Team for a bit now. and most of our listeners have an idea of what the Sinec Red Team does but it's been a minute. Do you mind sharing kind of what you do as a Sinec Red Team member? Of course.

So I've been on Sinec Red Team for about three months, three and a half months. So I know other people on your podcast have been here for years and years. So I'm pretty much a newbie compared to everybody else. but part of my day-to-day on SYNAC is I am responsible for reporting vulnerabilities ethically so I go through see what I can find and it's my responsibility to produce the best looking report I can and ship it off to SYNAC to review and send to the client.

Nice and now is it one target for like two weeks and that's all you're doing for like eight hours a day every day for those two weeks? No, no. So there's a variety of different targets on Sinec. So I kind of do a little bit of bunny hopping.

So I'll spend, you know, maybe a day or so on a target. And if I get bored, I'll swap to another target. And it's pretty much like hopping all over the place. So yeah, lots to choose from.

Lots to choose from. But it's not like just open bug bounty. You can't just go and pentest the world and then throw out a report. You've got specific targets, right?

Correct. Yes. Yeah. So it's not like, you know, I can boot up and go hack Microsoft.

There's specific, there's a specific scope and a specific set of targets that I'm legally allowed to test on. So, yeah. Yeah. I think Microsoft's a level eight client.

So, yeah. So you've been here for three months, you said, and I know we start at like level one and then you've got to turn in certain level of vulnerabilities and get those accepted by the VolNOPs team. And they're looking for, is it exploitable? Can they duplicate it?

Is your, like the information that you put into the form to go to the client, is all that accurate? And then based off of that, you get paid and you get points and that's how you move up and of the different levels. What level are you at now? So currently I'm level five.

So I'm at the top of the food chain right now. I'm kind of shocked that I hit level five in the timeframe that I did. I've talked to some other people and it's taken them years to hit level five. So I was pretty blown away when I got that email saying like, hey, congratulations, you hit level five.

So definitely was a shock. Nice. Well, what's different about you? Have you been pen testing things since you were able to read or what was your hacker origin story?

So in terms of my origin story, I mean, I've always been infatuated with computers. From a young age, I actually did a lot of video game mods. So I used a program called Cheat Engine, which is a debugger to inflate my health or the items that I had. So then I was like, okay, this is pretty cool.

And as time and time went on and I grew older the WannaCry ransomware back in 2017 hit and I was like like I didn realize that something could affect so many people And I was like, this is a field I definitely want to dive into. And then in 2018, when WikiLeaks happened with like the big NSA scandal with the spyware tools, I was like, this is the field I definitely want to spend the rest of my life in. This is just so fascinating and so. so I went to college I got my degree in cyber security and that's kind of my origin story as a hacker and then during my day to day I am a security consultant for a cyber security firm so I do a lot of pen tests daily non-Synac and yeah I spend the rest of my time on Synac content Wow What got you interested in the Synac Red team?

So I have a bunch of buddies who are in the SYNAC Red Team program. They're kind of my mentors. I definitely wouldn't be where I am today without them. So an insider threat, Logue and Ferdum, all three are very well-established SYNAC Red Team members.

And I believe Logue is on the circle of trust as well. So they kind of got me connected with SYNAC. And funny enough, I actually got denied my first time around. And that kind of pushed me to try harder.

What happened was I just didn't have enough certifications at the time and didn't build up my experience. So as soon as I got that denial letter, I immediately worked on my OSCP, passed that, and reapplied, and I was able to get in. Nice. That's awesome.

I've been denied a lot of things, and then you've got to hack your way in. So I very much understand. What's been your favorite part of being on the Senec Red team? Honestly, so there is a lot of public programs like HackerOne and BugCrowd.

Those are some of the most popular open source bug hunting platforms in the world. The issue with them is they're very competitive. So you can find a lot of valid issues, a lot of them critical, high, and they pay well, except it's you versus 10,000 people. So it's very hard to get a bug that actually sticks and lands.

what I like about on SYNAC is the competition is much shorter, like much smaller. So, you know, instead of going against 10,000 people, you're going against 300 people. And on top of that, especially if you're in some special cohorts, or for example, since I'm from the United States, I get to hunt on FedRAMP targets, the competition even gets smaller. So that's what I love about SYNAC is there's not a lot of competition and the triage time is insanely fast.

Like for example, I had three SQL lies I submitted two days ago and they're already triaged. They got triaged yesterday. And on these public programs like HackerOne, BugCrowd, you know, resolution can take weeks to months and it takes a while to get your payout. So, you know, I'm very grateful for in it.

Yeah, our Volnops team works fast. Yes. Have you ever been called back or gotten a notification for a patch verification? I have.

I just did a patch verification the other day on a FedRAMP target. Nice. If anyone who's listening doesn't know what a patch verification is, it's where you submit a valid vulnerability, the client deems it as an actual security issue, and they kick it back to you once they've attempted a patch for you to verify, hey, does this patch work? And if not, how can it be bypassed?

And it's essentially a big back and forth between you and the client. If it's not patched, it get kicked back and then they kick it back and it just a back and forth Yeah How do you feel about that I know you do pen testing as a consultant You probably done bug bounty in the past it sounds like. Is this different? Is this new?

In terms of like, like the communication and the back and forth on patch verification. No. So in my day-to-day job, I do a lot of back and forth between clients. Like, for example, you know, I'll find multiple vulnerabilities on a client's web app.

And usually how it works is once they feel like they've patched it, they send me a message and they're like, hey, can you double check that this is patched? So this is really nothing new. And I see it a lot of times on HackerOne where they'll invite you and be like, hey, can you test this and make sure that it's patched? And then they'll send you like 50 bucks or however much they deem is necessary for patch verification.

Nice. So you can do the other platforms and be on the Sinek Red team. Correct. Nice.

But I just choose Sinek because Sinek's better. I get that. I get that. I hear that from a lot of Sinek Red teamers.

Yeah. We've had Ty and Adam on We're In recently, and they have said the same things. Is there a favorite target? or not, don't tell me the company or the organization, but has there been one that you've just loved working with?

And do you have any stories without too many specifics of why? So there was a financial services platform that was on Sinek and it was a United States only target. So anytime I see United States only target, kind of a light bulb goes off in my head because I'm like, you know, I'm one of only 100 people hunting on this. Maybe not even that many.

Maybe it might be smaller than that. And I was assigned a bunch of different roles. So like there's an administrator, there was a fraud administrator, there was a regular customer role, and it was a dashboard. So what you could do is if you were a fraud administrator, like you could go in and configure fraud amounts.

And if you're an administrator, you could do things like user configs and all that stuff. But the default role had no permissions on the dashboard. If you logged into the dashboard, it would just be a blank page. And to do these privileged requests, there was an admin user ID that was appended onto every request.

Now, from this low privileged user, you never got that. You could never see a request where you could get your admin user ID, except when you inspected your JWT token. If you inspected your JWT token, inside was your admin user ID. And I used that and was able to compromise the entire platform and essentially do every single action on that financial services application.

So that was a really cool app. Whoa. One of those, I want to be admin. And so you make yourself admin.

Yeah. Yeah. And you're like, whoa, I can't believe this actually worked. Yeah.

glad you found it yeah that's pretty huge if someone was interested in joining the SYNEC Red team you've recently gone through the process you've been denied and came back what would what would you recommend to someone who's like you know what I like pen testing I want to be on that team honestly from my experience I would highly recommend getting some certifications you know not I feel like I was kind of conquering the infinity stones collecting all these certifications But I would say the one certification to go after is definitely the OSCP Because not only does it look good towards SYNAC it looks good in your professional life because it a very highly sought after certification It very hard to.

So I really like a challenge and OSCP definitely was a big challenge. So highly recommend knocking out some certifications because my issue was I had a decent chunk of experience, just not the certs to back it up. So definitely knock out those certs. That's huge.

That's huge. My only pen testing cert is EJPT, the United Security Junior Pen Tester. And I took that so that I could rewrite the course and make version two. Nice, nice.

Yeah. It is often something I hear, and it's good to have a few of those under your belt to get into the system. That makes a lot of sense. What about just someone in general?

You've been in cybersecurity for a bit now. Not necessarily a Cynic Red Team member, but what piece of advice would you have for anyone who's, you know, they saw something in the news like you did a few things and went, I want to be in cybersecurity. You've been here for a minute now. What piece of advice would you have?

Always keep learning. This field constantly changes on a day to day basis. So one of the things I like is I have a very short attention span. So if I learn everything about a field, I can get very bored very quickly.

And the one thing I love about this field is that you can never stop learning. There's always something to learn. And especially if you take that push to learn different techniques, you can open yourself up to a variety of opportunities. So like, for example, what I do is I actively scour HackerOne's hacktivity reports and also some various like bug bounty newsletters.

And I'll research some techniques, learn different things, and then I'll apply it to SYNAC. And I've noticed a lot of the times that the same techniques that other people use tends to work on SYNAC as well. And especially if you push yourself to learn more material, you can find yourself climbing up the ranks really fast. that makes a lot of sense do you have a specialty i know i've talked to ty and uh he likes a lot of the uh understanding the underlying business systems and the flows i've talked to a few who are big into injection they just go and they find everything that they can inject and see what works there uh some folks are really big on the i-door um do you have like a specialty um i would yeah so So my specialty, I would say, is authorization and injection issues.

That's kind of what I spend a lot of my time hunting on Synac for, because I also like to, you know, like time is money for me. So I don't want to go after the low-hanging fruit, like the CAPTCHA bypasses. Like that's not worth it to me. So I go after the heavy hitters.

So I specialize in a lot of eye doors, auth issues, like for example, that financial services platform. I just completely demolished their authorization schema. So, and SQL injections as well. I've been getting into that.

There's some Sinec Red Team members who are very well-versed and have kind of taken me under their wing, which I appreciate. But like, I'm definitely not a pro in injections by any means, but that is definitely something I'm working towards. I get that. That's awesome.

Well, Austin, it has been great talking with you.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • AI Finds Vulns You Can't With Nicholas CarliniSecurity Cryptography Whatever · on SQL injection100 / 100
  • Ship It Conversations: Kat Traxler of Vectra AI on AI Security, the Zero-Day Clock, IAM, and Cloud RiskShip It Weekly · on SQL injection96 / 100
  • How Founder POV Helps Sales Build Buyer Confidence with Jim Wilson, Partner at Costanoa Ventures - Ep 84The Transaction · on Bugcrowd85 / 100
  • Your Sales Team is now a DeveloperThreat Talks · on HackerOne84 / 100
  • Chris Pogue: Digital Forensics in the Modern Threat LandscapeKitecast · on SQL injection82 / 100
  • An AI Just Out-Hacked 2 Million Humans. She Decides What Happens Next | Nidhi Aggarwal, CPO HackerOneCXO Spotlight · on HackerOne80 / 100

More from WE'RE IN!

All episodes →
  • Getting Paid to Break Stuff with Ty Bross, SRT
  • The 9-Year SRT Veteran: Ozgur Alp on the Evolution of Hacking
  • From Bikes to Bytes: Breaking into Security with Tim Nordvedt
  • Teri Green: "AI is Artificial, YOU are the Intelligence!"
  • From 14-Year-Old Bug Hunter to Level 5 SRT Hero
Explore the best B2B Engineering & DevTools podcasts →
All WE'RE IN! episodes →