Seeking LIA / Internship · Nov 2026 – June 2027

Erik Nilsson

> secsson · Studying IT Security & Working Toward Offensive Security

Penetration testing student at IT-Högskolan, currently on Advanced Network Penetration Testing. I did a year of .NET web dev before switching over — I just really like breaking stuff.

Mainly digging into web AppSec, Active Directory, and building clean, reproducible PoCs. Big fan of utilizing modern AI tooling (Claude Code, Codex) to work faster and automate repetitive workflows, backed by strict manual verification.

🎯 Actively seeking an offensive security LIA / internship for November 2026 — June 2027.
1
Rewarded Bounty (Medium)
Valid Dupes
Method Validated by Triage
Sweden
IT Security Student
100%
PoC-Proven Submissions

Current Focus & Learning Areas

Core areas I am actively studying, practicing in labs, and targeting in bug bounties.

Web AppSec & Access Control

Focusing on core web vulnerabilities: IDORs, Broken Object Level Authorization (BOLA), session management flaws, authentication state transitions, and business logic omissions using Caido and modern testing workflows.

Caido IDOR / BOLA Broken Access Control Logic Flaws

Active Directory & Internal Pentesting

Hands-on experience from penetration testing studies analyzing Active Directory environments, mapping attack paths with BloodHound & RustHound, evaluating Kerberos/LDAP misconfigurations, and privilege escalation vectors.

Active Directory BloodHound RustHound Privilege Escalation

Source Code & .NET Application Analysis

Leveraging a foundation in .NET web development (C#, ASP.NET) to trace request lifecycles through codebases, spot subtle input validation misses, and understand how backend frameworks enforce authorization.

C# / ASP.NET Code Review Git Diffing Boundary Checks

AI-Assisted Workflow & Reporting

Utilizing agentic tooling (Claude Code, Codex, OpenCode) as practical accelerators for code navigation, test harness construction, and script automation. Grounded in a verification-first mindset — treating AI output strictly as hypotheses that require rigorous manual validation, PoC confirmation, and standards-compliant reporting.

Claude Code Codex OpenCode Verification-First Report Standards

Bug Bounty Track Record & Valid Findings

An honest overview of my real-world triage history. In bug bounty, duplicates are proof of valid vulnerability detection — each report sharpens the methodology.

In-Scope Bug Bounty Program Medium Severity Bounty Awarded & Resolved
Vulnerability identified on active production target, verified by triage, resolved by engineering, and awarded a bounty.
Active Bug Bounty Scope Confirmed unduped finding Reproducible step-by-step PoC
Valid Duplicates Real-World Validation

Hunting Real Production Targets

Actively hunting on competitive public and private programs. Multiple submissions have been triaged and confirmed as legitimate, reproducible vulnerabilities (duplicate status). In bug bounty, valid duplicates prove that the detection methodology is spotting real bugs in production — the current focus is closing the timing gap and hunting newly deployed features and changes.

Education & Skills

Academic training, self-directed security research, and technical toolkit.

Actively Seeking LIA November 2026 — June 2027

Offensive Security / Penetration Testing Internship

Looking for a practical LIA (internship) placement as part of my Higher Vocational Education at IT-Högskolan. Eager to contribute to a penetration testing, red teaming, or application security team (Sweden or remote).

Discuss Placement
2025 — 2027
Penetration Tester (Higher Vocational Education)
IT-Högskolan — Sweden

Two-year vocational programme specialized in offensive security and practical penetration testing.
Completed: Introduction to Penetration Testing · Networks and Network Security · Secure OS Configuration · Programming for Pen Testers · Hacking and Vulnerability Analysis · Active Directory · Application Security and Web Penetration Testing.
Current: Advanced Network Penetration Testing.
Upcoming LIA (Internship): November 2026 — June 2027.

2024 — 2025
Web Development in .NET (1 of 2 years)
EC Utbildning — Sweden

Studied HTML/CSS, JavaScript, C#, ASP.NET and relational databases at an introductory level. Switched tracks to IT security after the first year — having practical insight into how web applications are built makes it much more intuitive to reason about how they break.

2026 — Present
Bug Bounty & IT Consulting (Enskild Firma)
Sole Proprietorship · Innehar F-skatt & Moms · Sweden

Operating a registered Swedish sole proprietorship for bug bounty earnings and independent IT consulting. Active on competitive public/private programs with rewarded findings and valid duplicates, and available for freelance consulting and security assessments alongside studies.

Languages

Python Bash C# / ASP.NET JavaScript HTML / CSS SQL

Tools & Environment

Caido BloodHound RustHound Claude Code Codex OpenCode Linux CLI Git Docker Postman / cURL

Competencies & Methodologies

Active Directory Pentesting Report Writing (Current Standards) AI-Augmented Security (Verification-First) Web AppSec (OWASP Top 10) Reproducible PoCs Honesty Over Hype Responsible Disclosure

Contact

Feel free to reach out for collaboration, questions, or junior security opportunities.

Currently seeking an offensive security / penetration testing internship (LIA) for November 2026 — June 2027. Whether you have an open placement, want to discuss application security, or talk bug bounties, feel free to reach out directly via email or LinkedIn.

secsson@pm.me
Email: secsson@pm.me
GitHub: @secsson
Security Policy: /.well-known/security.txt
Enskild Firma Innehar F-skatt · Momsregistrerad

Registered sole proprietorship in Sweden for bounty income and IT consulting. Available for select freelance security assessments, code reviews, and IT consulting alongside studies.

Consulting Inquiry