@redroot97

Senior offensive security engineer. Core contributor to red team operations and enterprise penetration testing, spearheading purple-team validation across web, Active Directory, and cloud estates. Ongoing offensive-side research covers adversary simulation, custom tooling, and CVE discovery - partnering with detection engineering to harden the systems I break.

CVEs
11
YRS OFFENSIVE
6+
CERTS
7
[0x01]

$ whoami

// the short version

Senior Security Engineer specializing in offensive operations, adversary simulation, and the discovery of high-impact vulnerabilities across enterprise environments. Key contributor to red team operations and the driving force behind purple-team validation at a Fortune 50 healthcare organization.

Six-plus years of progressive experience across web, mobile, thick-client, and API penetration testing, Active Directory and cloud red teaming, and C2 infrastructure development. Author of custom offensive tooling, including the EBCDitor Burp extension for EBCDIC-encoded IBM mainframe traffic, Cobalt Strike BOFs for engagement-specific tradecraft, and automation pipelines that map adversary TTPs to MITRE ATT&CK and route them into purple-team workflows.

Current research focuses on CVE discovery in third-party enterprise software, integration of large language models into offensive telemetry analysis, and detection-friendly red team infrastructure built around VECTR, BloodHound Enterprise, and Brute Ratel C2.

Interested in advancing red team programs, adversary-simulation capabilities, and offensive research collaboration - reach out.

redroot97@kali:~
$ whoami --verbose
 
handle........: @redroot97
role..........: Sr. Security Engineer
focus.........: red team // pentesting // purple team // adversary sim
specialty.....: web, AD, cloud, mobile, thick-client, network, IoT
edu...........: M.S. Cybersecurity, UNCC
certs.........: OSCP, OSEP, CRTP, CESP, CEH, CRTO, CRTO 2
location......: United States
cves..........: 6 published // more pending
 
$ _
[0x02]

$ ls ./capabilities

// what I actually ship
[ engagement ]
Red Team Operations
End-to-end adversary simulation against enterprise environments. C2 infrastructure with Cobalt Strike & Brute Ratel. Custom BOFs, OPSEC-aware payloads, AD exploitation, lateral movement, persistence.
cobalt-strike brute-ratel
[ assessment ]
Application Pentesting
Web, mobile, thick-client, and API assessments. Mainframe pentesting via TN3270/EBCDIC. iOS reversing. Source-code review. Hunting auth/access bypasses, deserialization, race conditions.
burp mobsf corellium
[ platform ]
Enterprise Purple Team Platform
Designed and built an enterprise-grade purple team platform - functionally comparable to Cymulate - that continuously executes MITRE ATT&CK TTPs against production systems. Deep AWS Bedrock integration drives AI-assisted telemetry triage, detection-gap analysis, and detection-engineering feedback loops, with results piped into VECTR and Attack Forge.
aws-bedrock vectr mitre-att&ck
[ research ]
CVE Hunting
Vulnerability research in enterprise software, EDR/security tooling, and infrastructure components. Coordinated disclosure. Recent reservations target widely-deployed products.
[ cloud ]
Cloud + Kubernetes
AWS attack paths, container escapes, K8s cluster hardening. Built DNS-vulnerability automation at Amazon - dangling NS/A/CNAME detection across the org's record set.
aws k8s kube-hunter
[ tooling ]
Custom Offensive Tools
I write tools when the existing ones don't fit. EBCDitor Burp extension for mainframe traffic. Detection-aware C2 BOFs.
[0x03]

$ cat ./experience

// trail
JAN 2025 - PRESENT
Senior Security Engineer [ red team, purple team, pentesting, CVE research ]
CVS Health (Fortune 50 Healthcare) - Remote
Core contributor to red team and penetration testing across enterprise services and infrastructure. Built and spearheaded an enterprise purple team platform with AWS Bedrock integration. Drove CVE discoveries in Zscaler and macOS security controls.
MAR 2023 - JAN 2025
Red Team / Penetration Tester [ red team, adversary simulation, C2, tooling ]
Northwestern Mutual (Fortune 500 Financial Services) - Milwaukee
Web, mobile, thick-client, and mainframe pentesting. Wrote Cobalt Strike BOFs and the EBCDitor Burp extension. Built C2 infrastructure with Brute Ratel. Partnered with detection engineering on purple-team coverage for every TTP fired.
MAY 2022 - AUG 2022
Security Engineer Intern [ cloud security, DNS, automation ]
Amazon - Seattle
DNS security controls and dangling-record detection automation across Amazon's internal infrastructure.
JAN 2020 - MAY 2021
Security Consultant [ red team, pentesting, cloud, IoT ]
SecureLayer7 - India
Red team engagements against AD environments. VA/PT across thick clients, Kubernetes, Docker, iOS, IoT, and AWS. Onsite insider-threat pentests and social engineering.
AUG 2021 - DEC 2022
Teaching Assistant [ secure programming, pentesting ]
University of North Carolina, Charlotte
Built vulnerable labs and authored source-code-review CTF challenges for secure programming and pentesting courses.
JAN 2019 - JAN 2020
Junior Cybersecurity Analyst [ network, web, mobile ]
Wity Technology Corporation - India
Network, wireless, web, and mobile VA/PT. Built secure virtual labs for exploit development and PoC creation.
[0x04]

$ ./arsenal --list

// tools // certs // stack

// certifications

OSCP OSEP CRTP CRTO CRTO 2 CESP CEH

// education

M.S. Cybersecurity - University of North Carolina, Charlotte // 2022
B.E. Computer Science - Easwari Engineering College // 2019

// recognition

Winner - National Level Cybersecurity Hackathon // VIT × Wity, 2018

// offensive stack

Cobalt Strike Brute Ratel C2 Burp Suite Metasploit BloodHound Nmap Nessus SQLMap Nikto Dirbuster SET Immunity Debugger Wireshark Echo Mirage Postman MobSF Corellium Kube-Hunter Kube-Bench VECTR Attack Forge Exif Tool Process Hacker

// dev & ops

Python PowerShell Bash C / C++ AWS Kubernetes Docker Grafana Amazon Bedrock
[0x05]

$ ./contact

// direct channels
redroot97@kali:~/contact
$ cat contact.txt
 
 
// avg. response time: <24h