|
I’m Sergey “r0binak” Kanibor — a cybersecurity engineer and tech lead focused on kubernetes security, cloud security, and container security. Most of my work is about helping companies understand how their clusters and cloud can actually be hacked — and then making sure it is me who does it first. My background sits at the intersection of cloud-native engineering and offensive security: Kubernetes, containers, service meshes, CI/CD pipelines, AWS / GCP / Azure infrastructure, admission control, supply-chain security, developer tooling, SSDLC, threat modeling, and large-scale vulnerability assessments. |
┌─[r0binak@Kanibor.expert]─[~/ops] └──╼ ./profile --brief [+] role : r&d / container security / tech lead [+] focus : k8s, cloud, containers, pentest [+] mindset : offensive, practical, result-first [+] output : bugs, PoCs, tooling, risk maps, articles |
|
Cluster security reviews, RBAC and admission control, pod security standards, network policies, and the kind of misconfigurations that look harmless until a pod starts talking to the metadata endpoint. |
AWS / GCP / Azure security: IAM and privilege escalation paths, exposed control planes, storage and secrets hygiene, cloud-native detection gaps, and business logic that quietly grants far more access than intended. |
Image and supply-chain security, registry hygiene, container escapes, runtime hardening, CTF/bug bounty background, and occasional late-night experiments with things that should not break out like that. |
> I like security work that produces something concrete:
a reproducible exploit, a working PoC, a clear risk map,
a hardened configuration, a fixed architecture, or a painful
business-risk conversation that should have happened earlier.
- Built and led security teams across cloud-native platforms, AI platforms, and consulting.
- Worked with systems ranging from Kubernetes clusters and container registries to multi-cloud infrastructure and developer tooling.
- Still enjoy getting hands-on with Burp Suite, kubectl, Trivy, Falco, nmap, logs, traces, packet dumps, and a good YAML linter.
- Active around bug bounty and CTF culture, with a few Hall of Fame mentions along the way.
- Occasionally comment in media on cybercrime, cloud breaches, digital risks, and the practical side of defensive security.
/ research notes / small security tools
/ PoCs / cluster hardening guides
/ 0-day,1-day / container escape sploits
/ threat models / cloud & k8s architecture notes
I’m usually interested in work where security is treated as an engineering and business problem, not a ritual exercise.
Good reasons to reach out:
- security review of an application, platform, or critical business flow;
- penetration testing with realistic attack scenarios and practical remediation;
- threat modeling and security architecture for enterprise systems;
- cloud, kubernetes, containers, gitlab;
- weird bugs, exploit ideas, research notes, or tools worth building.
result != "list of vulnerabilities"
result == "clear attack paths + business impact + prioritized fixes"



