Skip to main content

About

Background #

I am a security researcher with experience in penetration testing, software engineering, and IT operations spanning over 20+ years. My areas of expertise include software application security, secure software development lifecycle, and platform security. As an active researcher, I have disclosed multiple critical and high-severity findings to Government, Fortune 500 organizations, small businesses, and open-source software projects. I regularly participate in bug bounty programs, conferences, and responsible disclosure.

Capabilities #

  • Clear & Closed-Box Web Application / Web API Security Assessments
  • Clear & Closed-Box Desktop Client Application Security Assessments
  • Secure Code Review
  • Internal and External Network Penetration Testing
  • Cloud Security Assessments
  • Mobile Application Security Assessments

Credentials #

Red Hat Certified System Administrator #

Red Hat

An IT professional who has earned the Red Hat® Certified System Administrator (RHCSA®) is able to perform the core system administration skills required in Red Hat Enterprise Linux environments. The credential is earned after successfully passing the Red Hat Certified System Administrator (RHCSA) Exam (EX200).
Red Hat Certified System Administrator

Certified Kubernetes Administrator #

Cloud Native Computing Foundation

Earners of this designation demonstrated the skills, knowledge and competencies to perform the responsibilities of a Kubernetes Administrator. Earners demonstrated proficiency in Application Lifecycle Management, Installation, Configuration & Validation, Core Concepts, Networking, Scheduling, Security, Cluster Maintenance, Logging / Monitoring, Storage, and Troubleshooting.
Linux Foundation Certified Kubernetes Administrator

Certified AI/ML Pentester #

SecOps Group

The Certified AI/ML Pentester (C-AI/MLPen) is an intermediate-level exam designed to test a candidate’s knowledge of the core concepts involving AI/ML security.
SecOps Certified AI/ML Penetration Tester

Web Application Penetration Tester eXtreme #

INE Security

INE Security’s Web Application Penetration Tester eXtreme certification is a hands-on exam designed for cybersecurity professionals with intermediate to advanced expertise in web application security and penetration testing. This certification assesses and validates the advanced knowledge, skills, and abilities necessary for the role of a modern web application penetration tester.
AWS Certified AI Practitioner

AWS Certified AI Practitioner #

Amazon Web Services

Earners of this badge understand AI, ML, and generative AI concepts, methods, and strategies in general and on AWS. They can determine the correct types of AI/ML technologies to apply to specific use cases and know how to use AI, ML, and generative AI technologies responsibly. They are familiar with the AWS Global Infrastructure, core AWS services and use cases, AWS service pricing models, and the AWS shared responsibility model for security and compliance in the AWS Cloud.
Web Application Penetration Tester eXtreme

Offensive Security Web Expert #

OffSec

Certified OSWEs have a clear and practical understanding of white box web application assessment and security. They’ve proven their ability to review advanced source code in web apps, identify vulnerabilities, and exploit them. They use creative and lateral thinking to determine innovative ways of exploiting web vulnerabilities OSWEs are able to assist web development teams in creating and maintaining web apps that are secure by design. OSWE holders must complete the Advanced Web Attacks and Exploitation (AWAE) course with Offensive Security and pass a rigorous 48-hour practical exam.
Offensive Security Web Expert

APISec University - API Penetration Testing #

APISec University

The API Penetration Testing course provides hands-on instruction on testing APIs for security flaws. Participants in the course have learned specific, detailed tools and techniques for analyzing, testing and identifying API vulnerabilities. The skills learned include API reconnaissance, scanning, auditing JSON Web Tokens, performing authentication and authorization attacks, and exploiting other common API weaknesses like injection, mass assignment, and server-side request forgery.
API Penetration Testing

Burp Suite Certified Practitioner #

PortSwigger

The Burp Suite Certified Practitioner is an official certification for web security professionals, from the makers of Burp Suite. Achieving BSCP status requires a deep knowledge of web security vulnerabilities, the correct mindset to exploit them, and of course, the Burp Suite skills needed to carry this out. Successfully passing the BSCP certification exam indicates a high-level proficiency in web security testing.
Burp Suite Certified Practitioner

Offensive Security Certified Expert #

OffSec

OSCEs have expert-level penetration testing skills. They have proven that they can craft their own exploits, execute attacks to compromise systems, and gain administrative access. The intense 48-hour exam also demonstrates that OSCEs have an above-average degree of persistence, determination, and ability to perform under pressure and can think outside the box to determine innovative ways of penetrating internal networks. An OSCE also has familiarity with more advanced protections like ASLR.
Offensive Security Certified Expert

Cloud Security Alliance CCSKv4 #

Cloud Security Alliance

Earners of the Certificate of Cloud Security Knowledge (CCSK) badge have demonstrated competency in key cloud security issues. They understand security best practices over a broad range of cloud computing domains. They have completed an examination covering the fundamental concepts of the CSA Security Guidance v.4, the CSA Cloud Controls Matrix v.3.0.1, and the ENISA white paper, “Cloud Computing: Benefits, Risks and Recommendations for Information Security”.
Cloud Security Alliance CCSK

AWS Certified Cloud Practitioner #

Amazon Web Services Expired

Earners of this certification have a fundamental understanding of IT services and their uses in the AWS Cloud. They demonstrated cloud fluency and foundational AWS knowledge. Badge owners are able to identify essential AWS services necessary to set up AWS-focused projects.
Web Application Penetration Tester eXtreme

Offensive Security Certified Professional #

OffSec

An OSCP has demonstrated the ability to use persistence, creativity, and perceptiveness to identify vulnerabilities and execute organized attacks under tight time constraints. OSCP holders have also shown they can think outside the box while managing both time and resources.
Offensive Security Certified Professional

CompTia Security+ #

CompTia Expired

Earners of the CompTIA Security+ certification have the knowledge and skills necessary to perform core security functions required of any cybersecurity role. CompTIA Security+ professionals know how to identify and address potential threats, attacks and vulnerabilities and they have established techniques in risk management, risk mitigation, threat management and intrusion detection. Earners of the CompTIA Security+ GFL understand network and data security principles that would help them build a general awareness of security threats and to understand basic principles of securing a network.
CompTia Security+

Professional Scrum Master #

Scrum.org

Those who earn the globally recognized Professional Scrum Master I (PSM I) certification have demonstrated a fundamental level of Scrum mastery, including the concepts of applying Scrum, and proven an understanding of Scrum as described in the Scrum Guide. This individual has also demonstrated a consistent use of terminology and approach to Scrum.
Scrum.org Professional Scrum Developer

Professional Scrum Developer #

Scrum.org

Those who earn the globally recognized Professional Scrum Developer I (PSD I) certification have demonstrated a fundamental level of professional software development, proving an understanding of the Scrum framework and how to work as part of a Scrum Team. This individual has also demonstrated an understanding of building useful and valuable Increments every Sprint and applying contemporary software engineering practices and tooling.
Scrum.org Professional Scrum Developer

CompTia Server+ #

CompTia

Earners of the CompTIA Server+ certification have the necessary skills to work in today's data centers, server rooms and cloud environments. CompTIA Server+ professionals have demonstrated mastery in the latest server technologies including virtualization, software-defined networking, security and network-attached storage.
CompTia Server+