A mid-size SaaS company sent two junior security analysts through Derivee Academy’s Web Application Exploitation cohort — an 8-week, hands-on program built around deliberately vulnerable applications rather than multiple-choice testing.
Both analysts graduated with working proficiency in authentication bypass, injection, IDOR, and business-logic testing. Within a month of completing the program, both were submitting and having verified findings accepted into their own company’s public bug bounty program.