Sungwuk Jung

Sungwuk Jung

Security Researcher

I'm Sungwuk, a Security Researcher with a passion for breaking things to make them safer! I'm currently focusing on Web/Mobile Penetration Testing and Red Teaming — always hunting for vulnerabilities and pushing security boundaries.

Work Experience

2025.11 – Present
Security Researcher @ Korea Information Systems Consulting & Audit Co., Ltd. · Gwacheon, Korea
  • Penetration testing (web / mobile) and red teaming across critical sectors — oil refinery, government institutions, university hospitals, and major enterprise companies
  • Red teaming engagements and exploitation of 1-day vulnerabilities
  • ISMS certification support through comprehensive security assessments
2025.06 – 2025.09
Security Consultant @ BlueTeamK · Seoul, Korea
  • Designed and implemented infrastructure vulnerability assessment scripts
  • Conducted analysis of global security incidents and built PoC demonstrations
  • Studied and applied the FAIR methodology for quantitative risk assessment
  • Led the development of technical and business proposals
2024.12 – 2025.03
Penetration Tester @ Fin Security · Seoul, Korea
  • Penetration testing (web / mobile) and security consulting across regulated industries — financial services, pharmaceutical, payment systems, and crowdfunding platforms
  • Compliance-driven assessments supporting ISO 27001 and ISMS certifications
  • Critical information infrastructure security evaluation

Education

2024.02 – 2024.08
Cloud Security Expert Course @ SK Shieldus Rookies class of 19 · Seoul, Korea
2018.03 – 2024.02
B.S. Computer Science @ Sangmyung University · Seoul, Korea
2015.09 – 2017.06
High Schcool Graduate @ Shanghai High School International Division · Shanghai, China

Disclosed Vulnerabilities & Bug Bounties

Awards

2018

Prize Sangmyung University Foreign Language Essay Competition Sangmyung University Encouragement Prize — Chinese Essay Category

Projects

🤖

AI-CVE-Scanner with AI API

AICVEClaudeGPT
🌱

Android application implementing rooted-device detection techniques and evaluating their bypasses. Published on Google Play Store.

AndroidKotlinSecurity
🖱️

Chrome extension that automates repetitive click actions. Published on Chrome Web Store.

Chrome ExtensionJavaScript
🛡️

Critical vulnerability implementations (File Upload, Path Traversal, Auth bypass, XSS, CSRF, SQL Injection) with secure-coding reviews for training and bypass practice.

Web SecurityOWASPSecure Coding
📱

Mobile security bypass research — rooting detection bypass, FLAG_SECURE capture-prevention bypass, PIN login bypass via response tampering, and ProcessBuilder 'su' detection evasion.

AndroidFridaBypassHooking
☁️

8-member team project (Project Manager role). Cloud-based financial application penetration test across three scenarios — asset hijacking, cloud resource takeover, mobile ransomware. Found XSS, SQL Injection, SSRF, and file upload vulnerabilities.

CloudPentestBurp SuiteMetasploitFrida

Certifications

  • 2025
    Engineer Information Processing HRD Korea

Blog Posts