Director, Red Team
Bentonville, Arkansas, Us
Built a world-class, geographically-distributed Red Team program combining existing and novel technical, social, and physical TTPs (Tactics, Techniques, and Procedures) to prepare the world’s largest company across 6 continents with more than 2 million associates and 200 million unique weekly customers, spread across legacy on-premise and cloud (Azure, GCP, and AWS). We created an innovative Rules of Engagement which enabled constant, multi-threaded adversarial pressure at Walmart scale to prepare the business to respond to real adversaries, while balancing the needs of our Blue Team peers. Partnering with our Quantitative Risk teams, we used the FAIR methodology to measure the loss magnitudes of our exercises like real incidents, to present the message in the language of the business.Additionally, the Red Team operated as a tech startup, streaming out adversarial capabilities using agile software engineering: - full CI/CD pipelines for our adversarial toolkit- custom, unit-tested stagers and implants to complement commonly available tooling (C++, C#, GoLang, Python)- safety checks, sandbox evasions, and canaries- custom hardware backdoors with 4G/LTE egress- smart centralized multiplayer backend (.NET, Redis, and open source)- custom phishing engines that matched our scale- spun up private collaboration tools & credential vaults- logged to our own ELK stacks- automated the creation of OPSEC-safe, ephemeral redirectors across a variety of providers in multiple countries- burned through hundreds of DNS domains per year with a curated, aging inventory- created our own Capability Maturity Models to measure our program over time and drive our investmentCo-founded Sp4rkCon, Walmart's free annual public information security conference.IN RUBRUM VERITAS