Skilled penetration tester and eager learner with a web development background. Proficient in web app vulnerabilities, coding, and various types of infrastructure penetration testing including red and purple team engagements, internal and external infrastructure review including Active Directory, cloud configuration reviews and mobile testing. My proficiency in communicating technical insights enables me to offer actionable recommendations, enhancing clients' security posture through clear and concise reporting.
Overview
4
4
years of professional experience
Work History
Lead Penetration Tester
Orange Cyberdefense (SensePost)
02.2022 - Current
Perform Purple Team engagements, develop custom payloads with C# and C++, emulating known threat actors and TTPs.
Conduct Red Team Engagements, including phishing and physical security assessments.
Perform web application and API penetration testing to identify and exploit vulnerabilities in web-based systems.
Conduct internal and external infrastructure penetration testing, including Active Directory.
Test mobile applications to identify and assess vulnerabilities in mobile environments including Android and iOS.
Conduct configuration reviews to identify and assess vulnerabilities in system configurations such as AWS, Google Cloud and Kubernetes.
Engage in research and development to stay current on industry trends and best practices in penetration testing and to write and deliver talks and blog posts, including a public talk at 0xCon 2024 around TTP emulation.
Communication with clients such as feedback calls to walk through security remediation.
Creation of training courses content on various topics such as Web App Hacking, Linux Privilege Escalation and SecDevOps.
Mentor junior team members in best practices for ethical hacking and penetration testing techniques, fostering professional growth among colleagues.
Created comprehensive documentation outlining test processes, results, and recommended actions for client review.
Full Stack Developer
Digital Humanity
09.2020 - 01.2022
Developed and maintained web applications and websites using the technologies listed below.
WordPress and PHP-based websites, experience in different page builders.
Developed and maintained a MEAN stack dashboard web applications using Angular and Node.js.
Maintained and managed a ruby on rails dashboard.
Conversion of Figma/adobe XD designs to front-end web pages and email templates using HTML, CSS JavaScript and PHP.
Setting up and administrating Linux-based web servers.
Managed source control using GIT.
JavaScript and PHP based scripting.
Creation and managing of Google ads campaigns.
Education
Offsec Wireless Professional -
01.2025
Offsec Certified Professional -
10.2024
Certified Ethical Hacker -
07.2023
Skills
Network penetration testing
Mobile application testing
Reverse engineering
Source code review
API security testing
Wireless security testing
Cloud security testing
Python
C#
C
OSCP
CEH
OSWP
Effective communication
Vulnerability assessment
Social engineering
Timeline
Lead Penetration Tester
Orange Cyberdefense (SensePost)
02.2022 - Current
Full Stack Developer
Digital Humanity
09.2020 - 01.2022
Offsec Certified Professional -
Certified Ethical Hacker -
Offsec Wireless Professional -
Similar Profiles
Steven GrumiauSteven Grumiau
Content Manager at Orange CyberdefenseContent Manager at Orange Cyberdefense