Senior offensive security engineer. Core contributor to red team operations and enterprise penetration testing, spearheading purple-team validation across web, Active Directory, and cloud estates. Ongoing offensive-side research covers adversary simulation, custom tooling, and CVE discovery - partnering with detection engineering to harden the systems I break.
Senior Security Engineer specializing in offensive operations, adversary simulation, and the discovery of high-impact vulnerabilities across enterprise environments. Key contributor to red team operations and the driving force behind purple-team validation at a Fortune 50 healthcare organization.
Six-plus years of progressive experience across web, mobile, thick-client, and API penetration testing, Active Directory and cloud red teaming, and C2 infrastructure development. Author of custom offensive tooling, including the EBCDitor Burp extension for EBCDIC-encoded IBM mainframe traffic, Cobalt Strike BOFs for engagement-specific tradecraft, and automation pipelines that map adversary TTPs to MITRE ATT&CK and route them into purple-team workflows.
Current research focuses on CVE discovery in third-party enterprise software, integration of large language models into offensive telemetry analysis, and detection-friendly red team infrastructure built around VECTR, BloodHound Enterprise, and Brute Ratel C2.
Interested in advancing red team programs, adversary-simulation capabilities, and offensive research collaboration - reach out.