cybersecurity manager & offensive security professional
Cybersecurity professional with 300+ accepted vulnerabilities on Bugcrowd, including P1 criticals on hardened targets like Square, Cash App, and FIS. Passionate about web, API, and mobile security with deep experience in red teaming, penetration testing, and vulnerability research.
Capabilities
Internal/external network pentesting and red team engagements. Phishing assessments, adversary simulation, and custom payload development.
Deep expertise in web and API vulnerability discovery. 300+ accepted bugs on Bugcrowd with P1 criticals on hardened targets. Focus on access control and authentication flaws.
Secure code review across Java, Python, and JavaScript. SAST/DAST/SCA integration into CI/CD pipelines. Shifting security left in the SDLC.
Static and dynamic analysis of iOS, macOS, and Android applications. Identifying hardcoded secrets, weak crypto, and hidden functionality.
Building custom scripts, scanners, and payloads for assessments. Automating reconnaissance, vulnerability scanning, and exploitation workflows.
Mapping findings to MITRE ATT&CK, OWASP, and CWE. Supporting compliance efforts aligned with FISMA and NIST 800 series standards.
Experience
Aug 2025 — Present
OnDefend — District of Columbia
Jan 2025 — Aug 2025
SIXGEN — Arlington
Jan 2023 — Jan 2025
Synack
Jun 2019 — Present
Bugcrowd / HackerOne
Jun 2021 — Jan 2023
Novavax — Gaithersburg
Aug 2015 — Present
Germantown Volunteer Fire Department
Research & Writeups
How I found a critical SSRF vulnerability that bypassed backend protections via an open redirect, exposing EC2 instance credentials — no authentication required.