Portrait of Marc-Oliver Munz

$ whoami

Marc-Oliver Munz.

aka c1phy

White-Hat & Elite-Hacker // HTB-Guru // Head of IT-Security // Freelancer

400+ VDP reports
1.5k+ Bug bounty reports
15+ Live hacking events
10+ Halls of Fame

// 01 intro

Who I am

c1phy character illustration
By a Belgian artist, celebrating my #1 spot on Intigriti

I'm Marc-Oliver Munz, a 35-year-old IT security professional based in the Stuttgart region, Germany, currently working as Head of IT Security. Over 19 years I grew through IT, from 1st and 2nd level support to administration and finally leading information security. Today my focus is building resilient security infrastructure and fostering a security culture in organizations.

My expertise covers both sides of security: defensive work around SIEM, XDR, SOC, NGFW and ISO 27001 compliance across the full IT infrastructure, and offensive, ethical hacking. I have led bug bounty programs and regularly take part in renowned live hacking events worldwide, including for Intel and Yahoo.

As an Intigriti Hacker Ambassador for Germany I bring the community together, share knowledge and help newcomers get into bug bounty and security research, and I promote responsible disclosure. My work has been recognized in halls of fame at Apple, the German armed forces (VDPBw), the Federal Office for Information Security (BSI), Heise, Deutsche Telekom and Mercedes-Benz.

  • Head of IT Security
  • 19+ years in IT
  • Ethical Hacking & Bug Bounty
  • SIEM · XDR · SOC
  • NGFW & Network Security
  • ISMS · ISO 27001 · NIST
  • Incident Response & Forensics
  • Security Awareness & Leadership

// 02 live hacking events

On the road

Live hacking events I took part in, from my first to what's coming up next.

Unranked Oct 2020

1st Kaeferjaeger LHE

Mannheim, Germany

Undisclosed

The first Kaeferjaeger live hacking event, where our German collective of around 40 hackers and security experts started its own self-organized LHE series.

Watch aftermovie
Unranked Oct 2021

2nd Kaeferjaeger LHE

Bonn, Germany

Undisclosed

Our second self-organized live hacking event with Kaeferjaeger, a German collective of around 40 hackers and security experts that I am part of.

Watch aftermovie
Top 5 Jun 2022

1337UP0622

Leuven, Belgium

Undisclosed

My first Intigriti live hacking event, on-site in Leuven, where I finished in the top 5 among experienced researchers. A formative milestone.

Watch aftermovie
Top 15 Aug 2022

1337UP0822

Antwerp, Belgium

Yahoo

Yahoo's European live hacking event with 40 selected researchers from across Europe and the US, supported by Intigriti, where I secured a top 15 finish.

Watch aftermovie
Top 3 Nov 2022

1337UP1122

Copenhagen, Denmark

Visma

Live hacking event in Copenhagen hosted by Visma and Intigriti, where my team placed in the top 3. An intensive review of Visma's cloud software products by experienced hackers.

Unranked Jun 2023

1337UP0623

Varna, Bulgaria

Undisclosed

A special opportunity to take part in the Intigriti live hacking event held in Varna, Bulgaria, hacking on-site alongside selected European researchers.

13th place Oct 2023

1337UP1023

Lisbon, Portugal

Intel

Selected among 100 elite hackers worldwide to harden the security of a brand-new Intel SaaS product, hosted by Intel and Intigriti.

Watch aftermovie
Unranked May 2024

German H1 Club Vol. 1

Bochum, Germany

Tools for Humanity

The very first HackerOne Club Germany hacking meetup, held in Bochum and targeting the Tools for Humanity program. Open to all skill levels, with a remote component.

Event page
Unranked May 2024

HH0524

Utrecht, Netherlands

Undisclosed

HackerHideout, an invite-only gathering where Europe's top bug bounty hunters, pentesters and ethical hackers meet in person. One venue, one day, plus pizza and war stories when the laptops close.

Event page
Unranked Feb 2025

German H1 Club Vol. 2

Bochum, Germany

Grab

Hybrid edition of the German HackerOne Club meetup with an in-person day in Bochum, hacking the Grab program alongside the club community.

Event page
1st place Jun 2025

German H1 Club Vol. 3

Remote only

Exness

Found the most critical bug of the 3rd virtual HackerOne Germany Club meetup and was awarded "Maximum Impact and Maximum Bounty" by Exness.

Event page
Unranked Nov 2025

1337UP1125

Leuven, Belgium

Undisclosed

Team live hacking of a large financial organization, with a scope of technically complex mobile and web applications. We achieved a strong placement and uncovered several high-impact vulnerabilities. Also awarded Intigriti's silver coin (250 valid reports) and gold coin (500 submissions).

Unranked Feb 2026

German H1 Club Vol. 5

Remote only

Undisclosed

Fifth edition of the German HackerOne Club hacking meetup, held remotely. A week-long hacking phase on a partner program, with a leaderboard and a closing remote meetup day for networking and show & tells.

Event page
Unranked Apr 2026

Intigriti Bug Bounty Meetup

Stuttgart, Germany

Undisclosed

The first Intigriti Bug Bounty Meetup in Stuttgart, which I founded and hosted as Hacker Ambassador for newcomers and experienced hackers alike.

Unranked May 2026

H1 In-Person Challenge

Berlin, Germany

Undisclosed

A HackerOne in-person hacking challenge in Berlin, bringing invited researchers together on-site for a focused round of collaborative bug hunting.

Upcoming Nov 2026

1337UP1126

Undisclosed

An upcoming Intigriti live hacking event later in the year. Looking forward to hacking on-site with the community again; further details to be announced.

// 03 recognition

Recognition

Ambassador roles, awards and hall-of-fame acknowledgements.

community Apr 2026

Founded the Intigriti Bug Bounty Meetup Stuttgart

Intigriti Ambassador

Organized and hosted the first Intigriti Bug Bounty Meetup in Stuttgart as Hacker Ambassador, bringing newcomers and experienced hackers together for talks, hands-on hacking and networking.

interview Feb 2026

Hacker Spotlight: From curiosity to critical bugs

Intigriti

Featured in Intigriti's Ethical Hacker Insights series, talking about my journey into bug bounty, notable findings and the mindset behind finding critical vulnerabilities.

award Jun 2025

1st Place - German H1 Club Vol. 3 (Exness)

Exness / HackerOne German Club

Found the most critical bug of the 3rd virtual HackerOne Germany Club meetup (Jun 2025), awarded "Maximum Impact and Maximum Bounty" by Exness and the highest payout of the event. The event paid out over $94,000 in bounties, a record for the series.

feature May 2025

SQLTimer featured in Intigriti Bug Bytes #224

Intigriti

My open-source tool SQLTimer, a fast Go scanner for time-based SQL injection, was featured in Intigriti's Bug Bytes newsletter (issue #224) as a useful addition to the bug bounty tooling community.

award Mar 2025

Emerald Legend (500 valid submissions)

Intigriti

Reached the Intigriti Emerald Legend milestone for 500 valid submissions, reflecting the sustained volume and quality of accepted vulnerability reports over years of continuous research on the platform.

community Oct 2024

Ambassador World Cup - Sweet Sixteen (Team Germany)

HackerOne

Active member of Team Germany in HackerOne's global Ambassador World Cup, a team-based live hacking tournament. Advanced to the Sweet Sixteen round against teams from around the world.

hall of fame Jul 2024

Deutsche Telekom

Deutsche Telekom

Discovered a broken access control flaw in a GraphQL interface of a Deutsche Telekom website; query manipulation allowed access to personal data (PII). Acknowledged in the Telekom Hall of Fame.

hall of fame Jan 2024

Federal Office for Information Security (BSI)

BSI

Continuous reporting to the Federal Office for Information Security since late 2022: 388 reported vulnerabilities, 290 of them already confirmed and fixed, actively strengthening cybersecurity.

hall of fame Jan 2023

Bundeswehr VDP (VDPBw)

VDPBw

Awarded the VDPBw coin for 39 confirmed vulnerabilities, including ATO, information disclosure, LFI, SQL injection, SSRF and cross-site scripting. Recognizes reporting a broad range of security threats.

hall of fame Jan 2023

Heise Group

Heise Group

Listed in the Heise Hall of Fame for reporting more than 10 security vulnerabilities, contributing to the security of Heise's digital platforms.

interview Jun 2022

Hacker Interview

Intigriti

Video interview with Intigriti, filmed at the 1337UP0622 live hacking event in Leuven, on my path into ethical hacking and bug bounty.

award Apr 2022

Intigriti #1 Program Leaderboard (R007 Ch13f)

Intigriti

Reached #1 on an Intigriti program quarterly leaderboard as R007 Ch13f, ranking ahead of all other researchers competing on that program during the quarter.

hall of fame Feb 2022

Mercedes-Benz AG VDP

Mercedes-Benz AG

Identified a critical vulnerability at Mercedes-Benz in 2022, leading to inclusion in the Mercedes-Benz Hall of Fame for responsible disclosure.

award Apr 2018

Guru rank at Hack The Box

Hack The Box

Reached the Guru rank on Hack The Box (HTB-Guru), a long-standing personal milestone reflecting deep hands-on offensive security skills.

// 05 certifications

Certifications

ISC2
  • CISSP (in progress)
CloudBreach
  • Offensive Azure Security Professional (OASP)
Cisco Systems
  • ICND1
  • IINS - CCNA Security
Microsoft
  • MCITP: Windows Server 2008
  • MCSA: Windows Server 2012
  • MCSE: SharePoint 2013
VMware
  • vSphere: Install, Configure, Manage
  • vSphere: Data Center Virtualization
ITIL
  • ITIL Foundation
  • ITIL v2011
Hewlett Packard Enterprise
  • H9P97S Managing HPE 3PAR StoreServ III
Industrie- und Handelskammer
  • Fachinformatiker Systemintegration
  • IT-Sicherheitsbeauftragter
  • Berufs- und Arbeitspaedagogische Eignung (AEVO)
  • Bachelor Professional of IT Business Management (CCI)

// 06 contact

Let's talk

Available on request for freelance security work: security consulting, penetration testing and more. Reach out.