Berend-Jan Wever
EN | NL
Introduction
Berend-Jan Wever is an offensive information security researcher whose work has evolved from low-level
discovery and exploit development to large-scale adversarial validation in AI-enabled systems. He specializes
in offensive research, fuzzing, automation, vulnerability analysis, and the design of scalable security
validation methods. Over the course of his career, he has reported hundreds of security issues across
operating systems, web infrastructure, cloud platforms, and complex distributed systems, impacting billions
of users.
His research combines systems-level understanding with adversarial thinking: he identifies how small flaws
compose into broader attack paths, traces root causes back to architectural and procedural weaknesses, and
builds the automated workflows needed to validate defenses at scale. This naturally extends into AI-focused
security research, where he evaluates adversarial techniques, prompt-injection risks, model abuse, and
detection gaps in AI-assisted environments.
Berend-Jan has spent decades working with security teams at some of the largest companies in the industry,
helping them move from isolated bug-finding to repeatable, scalable security programs. He develops
automation, suggests process changes, creates training, and designs validation frameworks that help teams
find and remove entire classes of weaknesses before they reappear. His work has consistently focused on
long-term impact: building methods that scale with product growth and remain effective as systems evolve.
He creates actionable reports for engineers and high-level risk assessments for management, advises on
remediation and mitigation strategies, and helps junior researchers grow by sharing techniques, tools,
and research methods. He enjoys presenting his work, discussing emerging threats, and pushing security
research forward into new domains such as AI-driven systems, adversary emulation, and automated security
review at scale.
Technology
Berend-Jan has worked across a broad range of platforms, languages, and security domains. The most
relevant areas are summarized below.
Operating Systems and Cloud
Microsoft Windows, Linux, Amazon Web Services (AWS).
Languages
Java, Python, JavaScript/TypeScript, C, C++, C#, PowerShell, Bash, SQL, assembly.
Security Disciplines
Fuzzing, reverse engineering, exploit development, adversarial emulation, threat modeling,
security automation, detection engineering, vulnerability analysis.
Platform Experience
Browsers, operating systems, cloud services, drivers, firmware, web infrastructure, and distributed
systems.
Recent Work History
Principal Security Researcher within Microsoft Azure Security Engineering
Location: Work from home in the Netherlands
Period: 2025-Present
Activities: adversary emulation, security research, security validation, automation, AI security research
This role reflects the natural progression of Berend-Jan's work from offensive research and automation to
AI-focused adversarial security validation, where the emphasis is on understanding emerging risks in AI
systems, validating defensive controls at scale, and translating adversary behavior into measurable,
repeatable security testing.
-
Led the development of attack-simulation and detection-validation capabilities used to measure the
real-world effectiveness of Azure security controls against adversary techniques and attack chains.
-
Established research methodologies for translating MITRE ATT&CK techniques into repeatable,
measurable attack simulations, enabling objective evaluation of detection quality, telemetry coverage,
and defensive effectiveness.
-
Drove strategic security research across Azure identity and infrastructure platforms,
uncovering security weaknesses, validating mitigations, and developing scalable
validation approaches.
-
Influenced detection-engineering investment by identifying systemic telemetry, observability, and
detection gaps through continuous adversary emulation and large-scale campaign execution.
-
Co-created a framework designed to scale attack simulation, campaign orchestration, and security
validation through automation and reusable workflows.
-
Championed the evolution from isolated attack testing toward chained adversary campaigns that assess
end-to-end detection effectiveness against realistic attack paths.
-
Partnered with Microsoft Red Team, MSTIC, detection engineering, and Azure service teams to strengthen
cloud security posture, validate mitigations, and accelerate remediation of identified weaknesses.
-
Helped define strategic approaches for AI-assisted security validation, detection generation, LLM
security, prompt-injection resilience, and emerging AI data-poisoning attack scenarios.
-
Advanced security automation by developing workflows, tooling, and research processes that improve the
scale, repeatability, and operational efficiency of attack research and validation efforts.
-
Developed an AI-based source code scanner designed to require no security or AI expertise from its users.
It replaces periodic manual security reviews by security experts with a continuous background
task that can be run by developers within the team.
Senior Security Engineer within Amazon Web Services (AWS) Holistic Testing Team
Location: Work from home in the Netherlands
Period: 2021-2024
Activities: team leadership, security reviews, threat modeling, automation, security training
-
Led 4-5 person teams through 2-3 month security reviews of critical AWS services, prioritizing testing
scope based on risk, service architecture, and likely impact to customers.
-
Drove end-to-end security assessments from threat modeling and architecture review through testing,
vulnerability analysis, remediation guidance, and executive reporting.
-
Identified systemic weaknesses and root causes across multiple services, helping teams shift from
isolated fixes toward scalable prevention strategies, training, and process improvements.
-
Designed and implemented automation to improve the efficiency, consistency, and coverage of security
testing, including scanning, validation tooling, fuzzing, and Proof-of-Concept development.
-
Standardized tool design and reporting formats to improve interoperability, reduce maintenance overhead,
and make security validation easier to repeat and extend across teams.
-
Worked with service teams and managers to translate technical findings into clear risk narratives,
remediation plans, and long-term security improvements.
Senior Security Researcher and head of Fuzzing Community at Intel
Location: Work from home in the Netherlands
Period: 2019-2021
Activities: technical leadership, fuzzing, automation, training, cross-team strategy
-
Established a cross-Intel effort to scale offensive security research and fuzzing through reusable
tooling, shared workflows, and better alignment between research teams.
-
Designed and led the implementation of a modular framework for automated security testing across virtual
and physical targets, enabling broad adoption with minimal setup overhead and expertise requirements.
-
Improved the effectiveness of fuzzing programs by making them easier to deploy, easier to extend, and
better suited to the realities of difficult-to-fuzz hardware, firmware, and driver targets.
-
Connected teams with similar goals to share discoveries, accelerate adoption, and build a reusable
security research capability that could extend beyond a single product area.
-
Created workflows for issue triage, deduplication, and reporting so that fuzzing results could be used
operationally to assess risk, track progress, and support SDL validation.
Owner of SkyLined Security
Location: Work from home in the Netherlands
Period: 2011-2019
Activities: security research, fuzzing, automation, consulting, research publications
-
Built and operated a high-impact offensive security research practice focused on automated vulnerability
discovery, exploiting weaknesses in major browser and platform components at scale.
-
Developed fuzzers and analysis tooling that uncovered a large
number of issues in high-profile targets, including Microsoft Windows, Microsoft Internet Explorer,
Microsoft Edge, Google Chrome, and Mozilla Firefox.
-
Reported enough vulnerabilities to Microsoft to be included in the
Microsoft Security Research Center Top 100 Security Researchers
list for three consecutive years from 2015.
-
Worked as an external consultant across a wide range of engagements, from penetration testing and code
reviews to custom fuzzer development, exploit research, and security guidance for product teams.
Senior Software Security Engineer in Chrome Security Team at Google
Location: Work from home in the Netherlands
Period: 2008-2011
Activities: security engineering, fuzzing, automation, patch validation, security process
-
Joined the initial Google Chrome Security Team and helped
ensure the browser shipped without major security issues within the first three months.
-
Built analysis and validation tools that covered nearly all areas of the codebase and remain in active use
to this day.
-
Identified and triaged large numbers of vulnerabilities, evaluated externally reported issues, and helped
guide rapid remediation to protect users at scale.
-
Strengthened product security through design and implementation changes, mitigation work, and direct
guidance to Chromium project members on security-sensitive engineering decisions.
-
Contributed to the launch and operation of the
Google Chrome Vulnerability Reward Program and developed fuzzers that continued to find issues in Chrome.
Security Researcher in Security Windows Initiative Attack Team at Microsoft
Location: Work from home in the United Kingdom
Period: 2005-2008
Activities: offensive security, fuzzing, design & implement automation, vulnerability analysis, research
-
Joined a newly formed security team as the European branch of the larger Windows initiative attack team,
helping establish a focused research capability in a high-impact environment.
-
Built more effective tooling for detecting security issues, including fuzzers and compiler plug-ins that
surfaced vulnerable patterns earlier in the development cycle.
-
Reviewed code, patches, and external vulnerability reports to assess impact and communicate technical risk
to product teams.
-
Explored new attack vectors and techniques and shared findings with developers to improve product security
across multiple teams.
-
Contributed to hiring and onboarding in the UK, helping grow a small research team into a stronger,
more capable security function.
Skills and Experience
Key skills
-
Experience in security on a wide range of products, including hardware, firmware, drivers, server software,
client software, websites, and AI-enabled systems, as well as process improvement and security education.
-
Individual contributor and tech lead. Enjoys guiding junior team members to help them exploit their strengths
and avoid/improve their weaknesses. Loves explaining techniques and tricks and giving tips on how to find,
analyze and address security weaknesses to anyone who will listen.
-
Research focus has evolved from offensive security and system exploitation toward AI-focused security
validation, adversarial emulation, prompt-injection assessment, and the evaluation of detection quality in
modern AI-driven environments.
-
Developed and deployed AI-based source code scanning workflows that identify security weaknesses across
sensitive internal systems without requiring security or AI expertise from end users, enabling continuous
review and proactive remediation at scale.
-
20 years of experience in fuzzing, both in creating fuzzers, using them to find issues and processing the
results to improve the security of a wide range of products. Knows how to avoid overwhelming a development
team with new findings by prioritizing and filtering based on severity/impact and development team size.
-
Thinks far outside the box and has a history of published innovative and creative security techniques to
prove it.
-
A wide range of projects has provided experience in a large number of topics. From user-land applications to
operating system kernels, firmware, and hardware. From design to implementation and configuration reviews, in
a wide-range in programming, scripting and markup languages. From client to cloud, through front-end,
back-end, proxies and servers, as well as the network layer. From protocols and file-formats to memory
layout and CPU features.
-
Comfortable and experienced with learning new programming languages, applications, frameworks and systems
on the job. The only think I have avoided is cryptography.
Historically Notable Publications
A small selection of contributions to the information security community:
-
BugId is a Python script that automatically analyzes crashes
and determine their security impact. It reduces the need for a large and costly team of specialized security
engineers. It reduce time-to-patch and window of exploitability by prioritize important issues and speeding up
analysis. It can create detailed reports containing both concise management-level information and extensive
technical details.
-
Browser Security Whitepaper
that collects all relevant information on the security of a number of different web browsers. It covers
everything from high-level configuration management to low-level security technologies. IT managers can use it
to make an informed decision about which browser is best suited for their specific needs. It offers security
experts evidence based data on which browser protects best against specific risks.
-
Released technical analysis of a large number of vulnerabilities and techniques.
-
Illustrated the fragility of state-of-the-art web browser code in 2016 through
daily Tweets about a new way to crash a
web browser.
-
Introduced
heap-spraying in web browsers, a technique that
facilitates exploitation of vulnerabilities in application. This technique has been widely adopted and built
upon to bypass mitigations and create sophisticated and reliable exploits.
-
Main author of the world's smallest Windows
shellcode.
-
Inventor of the concept of Omelette shellcode.
-
Creator of the first practical alphanumeric shellcode encoder,
which was ported to the Metasploit framework and
author of ASCII art shellcode.
-
Created the first Proof-of-Concept
XSS worm in 2002 to warn of their potential danger;
the first publicly released XSS worms proved
they can causing serious damage 3 years later.
Spoken languages
Dutch - native
English - Fluent
German - Proficient
French - Basic