About
Table of Contents
Background #
I am a security researcher with experience in penetration testing, software engineering, and IT operations spanning over 20+ years. My areas of expertise include software application security, secure software development lifecycle, and platform security. As an active researcher, I have disclosed multiple critical and high-severity findings to Government, Fortune 500 organizations, small businesses, and open-source software projects. I regularly participate in bug bounty programs, conferences, and responsible disclosure.
Capabilities #
- Clear & Closed-Box Web Application / Web API Security Assessments
- Clear & Closed-Box Desktop Client Application Security Assessments
- Secure Code Review
- Internal and External Network Penetration Testing
- Cloud Security Assessments
- Mobile Application Security Assessments
Credentials #
Red Hat Certified System Administrator #
An IT professional who has earned the Red Hat® Certified System Administrator (RHCSA®) is able to perform the core system administration skills required in Red Hat Enterprise Linux environments. The credential is earned after successfully passing the Red Hat Certified System Administrator (RHCSA) Exam (EX200).

Certified Kubernetes Administrator #
Cloud Native Computing Foundation
Earners of this designation demonstrated the skills, knowledge and competencies to perform the responsibilities of a Kubernetes Administrator. Earners demonstrated proficiency in Application Lifecycle Management, Installation, Configuration & Validation, Core Concepts, Networking, Scheduling, Security, Cluster Maintenance, Logging / Monitoring, Storage, and Troubleshooting.

Certified AI/ML Pentester #
The Certified AI/ML Pentester (C-AI/MLPen) is an intermediate-level exam designed to test a candidate’s knowledge of the core concepts involving AI/ML security.

Web Application Penetration Tester eXtreme #
INE Security’s Web Application Penetration Tester eXtreme certification is a hands-on exam designed for cybersecurity professionals with intermediate to advanced expertise in web application security and penetration testing. This certification assesses and validates the advanced knowledge, skills, and abilities necessary for the role of a modern web application penetration tester.

AWS Certified AI Practitioner #
Earners of this badge understand AI, ML, and generative AI concepts, methods, and strategies in general and on AWS. They can determine the correct types of AI/ML technologies to apply to specific use cases and know how to use AI, ML, and generative AI technologies responsibly. They are familiar with the AWS Global Infrastructure, core AWS services and use cases, AWS service pricing models, and the AWS shared responsibility model for security and compliance in the AWS Cloud.

Offensive Security Web Expert #
Certified OSWEs have a clear and practical understanding of white box web application assessment and security. They’ve proven their ability to review advanced source code in web apps, identify vulnerabilities, and exploit them. They use creative and lateral thinking to determine innovative ways of exploiting web vulnerabilities OSWEs are able to assist web development teams in creating and maintaining web apps that are secure by design. OSWE holders must complete the Advanced Web Attacks and Exploitation (AWAE) course with Offensive Security and pass a rigorous 48-hour practical exam.

APISec University - API Penetration Testing #
The API Penetration Testing course provides hands-on instruction on testing APIs for security flaws. Participants in the course have learned specific, detailed tools and techniques for analyzing, testing and identifying API vulnerabilities. The skills learned include API reconnaissance, scanning, auditing JSON Web Tokens, performing authentication and authorization attacks, and exploiting other common API weaknesses like injection, mass assignment, and server-side request forgery.

Burp Suite Certified Practitioner #
The Burp Suite Certified Practitioner is an official certification for web security professionals, from the makers of Burp Suite. Achieving BSCP status requires a deep knowledge of web security vulnerabilities, the correct mindset to exploit them, and of course, the Burp Suite skills needed to carry this out. Successfully passing the BSCP certification exam indicates a high-level proficiency in web security testing.

Offensive Security Certified Expert #
OSCEs have expert-level penetration testing skills. They have proven that they can craft their own exploits, execute attacks to compromise systems, and gain administrative access. The intense 48-hour exam also demonstrates that OSCEs have an above-average degree of persistence, determination, and ability to perform under pressure and can think outside the box to determine innovative ways of penetrating internal networks. An OSCE also has familiarity with more advanced protections like ASLR.

Cloud Security Alliance CCSKv4 #
Earners of the Certificate of Cloud Security Knowledge (CCSK) badge have demonstrated competency in key cloud security issues. They understand security best practices over a broad range of cloud computing domains. They have completed an examination covering the fundamental concepts of the CSA Security Guidance v.4, the CSA Cloud Controls Matrix v.3.0.1, and the ENISA white paper, “Cloud Computing: Benefits, Risks and Recommendations for Information Security”.

AWS Certified Cloud Practitioner #
Amazon Web Services Expired
Earners of this certification have a fundamental understanding of IT services and their uses in the AWS Cloud. They demonstrated cloud fluency and foundational AWS knowledge. Badge owners are able to identify essential AWS services necessary to set up AWS-focused projects.

Offensive Security Certified Professional #
An OSCP has demonstrated the ability to use persistence, creativity, and perceptiveness to identify vulnerabilities and execute organized attacks under tight time constraints. OSCP holders have also shown they can think outside the box while managing both time and resources.

CompTia Security+ #
CompTia Expired
Earners of the CompTIA Security+ certification have the knowledge and skills necessary to perform core security functions required of any cybersecurity role. CompTIA Security+ professionals know how to identify and address potential threats, attacks and vulnerabilities and they have established techniques in risk management, risk mitigation, threat management and intrusion detection. Earners of the CompTIA Security+ GFL understand network and data security principles that would help them build a general awareness of security threats and to understand basic principles of securing a network.

Professional Scrum Master #
Those who earn the globally recognized Professional Scrum Master I (PSM I) certification have demonstrated a fundamental level of Scrum mastery, including the concepts of applying Scrum, and proven an understanding of Scrum as described in the Scrum Guide. This individual has also demonstrated a consistent use of terminology and approach to Scrum.

Professional Scrum Developer #
Those who earn the globally recognized Professional Scrum Developer I (PSD I) certification have demonstrated a fundamental level of professional software development, proving an understanding of the Scrum framework and how to work as part of a Scrum Team. This individual has also demonstrated an understanding of building useful and valuable Increments every Sprint and applying contemporary software engineering practices and tooling.

CompTia Server+ #
Earners of the CompTIA Server+ certification have the necessary skills to work in today's data centers, server rooms and cloud environments. CompTIA Server+ professionals have demonstrated mastery in the latest server technologies including virtualization, software-defined networking, security and network-attached storage.
