Deployment log.

Two organizations, one trajectory — from security operations to leading red-team engagements. 3 roles logged since 2022.

Senior Executive, Red Team

BRACNet Limited — Cyber Security

 2024 — Present

Leading red-team attacks against customer environments — thinking and acting like a real adversary to validate defenses before attackers do.

Red Team Web Apps Mobile (Android/iOS) APIs Network Devices Servers
  • Perform red-team attacks against customer environments, simulating actual attacker tactics, techniques and procedures.
  • Conduct comprehensive vulnerability assessments on servers, identifying critical weaknesses and delivering actionable remediation strategies.
  • Penetration-test network devices, routers and firewalls to evaluate security configurations and recommend improvements.
  • Assess the security of web applications with thorough evaluations and detailed remediation reports.
  • Evaluate Android and iOS applications using both dynamic and static analysis techniques to uncover vulnerabilities.
  • Penetration-test APIs, identifying vulnerabilities and recommending security enhancements.
  • Collaborate with cross-functional teams to design and implement security measures protecting digital assets against evolving threats.
  • Stay current with the latest security trends and emerging threats, continuously improving testing methodologies and tools.

Executive Engineer, Security Operations

Enterprise InfoSec Consultants (EIC)

2024

Stepping up to provide direction and strategy for the security unit — translating security priorities into organizational outcomes.

Strategy Risk Leadership
  • Provided direction, strategy and oversight for the security unit.
  • Worked with other teams to align security objectives with organizational goals.
  • Identified and analyzed system, application and network vulnerabilities.
  • Assessed and prioritized potential risks and vulnerabilities.
  • Documented findings to improve the organization's security posture.

Engineer, Security Operations

Enterprise InfoSec Consultants (EIC)

2022 — 2023

The foundation — running assessments hands-on across the full attack surface and turning findings into fixes.

Web Apps Mobile (Android/iOS) APIs Network Devices Servers
  • Conducted comprehensive vulnerability assessments on servers, identifying critical weaknesses with actionable remediation strategies.
  • Penetration-tested network devices, routers and firewalls, evaluating security configurations and recommending improvements.
  • Assessed web application security, delivering thorough evaluations and detailed reports for remediation.
  • Evaluated Android and iOS applications using dynamic and static analysis techniques to identify vulnerabilities.
  • Penetration-tested APIs, identifying vulnerabilities and recommending security enhancements.
  • Collaborated with cross-functional teams to design and implement security measures against evolving threats.
  • Stayed updated on security trends, continuously improving testing methodologies and tools.
what that means

Same methodology, growing scope

From executor to owner

Started running individual assessments, moved to directing the security unit's strategy, and now own red-team engagements end to end.

Consistent full-stack coverage

Web, mobile, API, network and infrastructure assessments appear at every stage — the attack surface only widens as the role grows.

Delivery against real targets

The work has produced security assessments across banks, fintech platforms, IT services and development organizations.

view engagements →
credentials

The certifications behind the work