With over 22 years of experience in cybersecurity, I provide expert penetration testing, red team operations, and security consulting services to protect your organization from evolving cyber threats.
Cybersecurity leader with extensive expertise in penetration testing, web application security, and red team operations
I'm a seasoned IT professional with 25 years of experience, including 22 years specializing in penetration testing. As the former OWASP Houston Chapter Leader (2012-2014) and an OWASP Trainer, I bring a wealth of knowledge in offensive security operations.
My qualifications derive from four core pillars: military training and discipline as a U.S. Air Force Veteran (7.5 years), rigorous industry certifications, decades of hands-on experience at the highest levels, and recognized authorship contributions to the global application security community.
My formal education includes 42 competency units in the Cybersecurity program at Western Governors University (WGU), designated by NSA/DHS as a National Center of Academic Excellence in Cyber Defense. Additionally, I have completed 19 continuing education certificates focusing on the intersection of AI/ML and offensive security.
Comprehensive security solutions tailored to protect your organization's digital assets
Identify vulnerabilities in your web applications using manual techniques that go beyond automated tools, focusing on business logic flaws and OWASP Top 10 risks.
Comprehensive assessment of your network infrastructure to identify vulnerabilities that could be exploited by attackers to gain unauthorized access to your systems.
Expert testing of AWS, Azure, and Google Cloud environments to identify misconfigurations, access control issues, and other security vulnerabilities.
Simulate real-world attacks using advanced tactics, techniques, and procedures (TTPs) to assess your organization's detection and response capabilities.
Assess your organization's human security controls through phishing campaigns, vishing calls, and physical security tests to identify potential weaknesses.
Strategic guidance on security policies, standards, and procedures to help your organization build a robust security program aligned with industry best practices.
Over two decades of cybersecurity expertise across various industries
Conducting cloud adversarial emulation testing, developing custom payloads, and managing C2 infrastructure to bypass advanced security defenses.
Executed web application penetration tests across cloud infrastructures, identifying vulnerabilities and developing risk mitigation strategies.
Led weekly security assessments using hybrid DAST/AST methodology, working with a global team of 20 members to secure over 18,000 applications.
Conducted assessments using NIST 800-53 Rev.4, OWASP Testing Guide v4, and other frameworks, while developing custom security tools.
Formal academic training and verified professional development
Completed rigorous coursework in network security, secure software design, cryptography, and information assurance.
Active pursuit of OSCP. Verified continuing education in Offensive Penetration Testing, Ethical Hacking for Web Servers & Web Applications, and CISSP Prep.
Completed 11 advanced certificates including GenAI for Software Engineering, Agentic AI for Leaders, AI Agents with Python, Vibe Coding with Claude Code, and Enterprise AI Strategy.
Honorable discharge with a strong foundation in operational security. Awarded the Air Force Achievement Medal for exceptional service during Hurricane Katrina relief operations.
Contributions to the cybersecurity community and ongoing research initiatives
Research on the risks associated with unrestricted file uploads in web applications, including system takeover and information leakage vulnerabilities.
Read Publication
In-depth analysis of the EternalBlue exploit, examining how it targets SMB vulnerabilities and methods for effective mitigation.
View Research
Research on common misconfigurations in cloud access policies and serverless architectures that can lead to security breaches.
Explore FindingsGet in touch to discuss how I can help secure your organization