Independent security consulting and assessment predominantly for global financial services and investment banking clients.> 15 years cyber security (predominately penetration testing / ethical hacking) experience.Specialties: Penetration testing and vulnerability assessment specialist with experience in many ordinary and exotic domains including: NFC, Laptop TPM bypass, Wireless, Phishing, Red-Teaming, ATMs, API's, Applications (web, mobile and thick client), Infrastructure and networks, Windows domains, Unix and Linux builds.Strong application security knowledge and testing experience for common web and mobile frameworks (PhoneGap, Ionic, Angular, Express, Rails, Struts, ASP.NET etc).Performed third-party product due diligence of many financial COTS products.Experienced at exploiting weaknesses and misconfigurations in Single-sign-on solutions, SmartCard implementations, Citrix environments, Trading applications and Web services.Tailor technical assessment deliverable output so that they are appropriate for the client/reader i.e. risk managers, test managers, developers, CISO's etc.Development and scripting skills in Go, Python, Ruby, Java, Node, PHP.Safely demonstrated high profile attack scenarios including; Jackpotting ATM's, changing bank liquidity levels, compromising all applications and users at a major bank, remote unauthenticated thefts of intellectual property, Spear Phishing board level executives and many many more.Data driven to present and encourage strategic solutions to pen test defect root causes enabling businesses to focus on areas that will have the greatest impact.Driven to identify and implement more efficient working practices that reduce duplication of effort and repetitive time consuming micro tasks.
Listed skills include Penetration Testing, Vulnerability Assessment, Information Security, Application Security, and 14 others.