MELBOURNE, AU — OSCP

Extra hands
when your
bench is full.

Independent penetration tester available for overflow and subcontract engagements — web application, network, and mobile testing. Signed agreement, clear scope, and I can start within days.

OSCPCRTOAWS SAA
hexcipher ~ recon
$ nmap -sV -p- 10.0.0.1
→ 3 open ports, 2 outdated services flagged
$ nikto -h https://10.0.0.1
! outdated TLS config, verbose error leakage
$ node exploit-chain.js --scope engagement-4471
! auth bypass confirmed on admin panel
→ escalation path documented for report
Now booking overflow & subcontract pentest engagementsRemote-first delivery — travel available Australia-wideSigned agreement, clear scope, start within days$5,000,000 AUD professional indemnity & liability coverOutside-business-hours and short-notice scheduling availablePrimary focus: web application penetration testingNow booking overflow & subcontract pentest engagementsRemote-first delivery — travel available Australia-wideSigned agreement, clear scope, start within days$5,000,000 AUD professional indemnity & liability coverOutside-business-hours and short-notice scheduling availablePrimary focus: web application penetration testing
6+
years in offensive security
11+
industry certifications
5+
sectors assessed
$5M
AUD indemnity & liability cover
// SERVICES

Web app first.
Full-stack capability behind it.

01 - APPSEC

Web Application Penetration Testing

Primary focus. Manual testing for OWASP Top 10 and beyond — auth flaws, IDOR, injection chains, and business logic vulnerabilities.

02 - EXTERNAL

External Network Penetration Testing

Perimeter assessments against internet-facing infrastructure and services.

03 - INTERNAL

Internal Network Penetration Testing

Remote or on-site internal assessments — privilege escalation, lateral movement, and domain compromise paths.

04 - MOBILE

Mobile Application Testing (Android)

Android application security testing. iOS available on request.

05 - CLOUD

Cloud Security Review

AWS and Azure configuration reviews — IAM misconfigurations, exposed storage, and container breakout paths.

06 - REDTEAM

Adversary Simulation

Full-scope red team engagements available by request — not a core focus, but certified and experienced (CRTO, SpecterOps Adversary Tactics).

// METHODOLOGY

How we operate

01

Scoping & threat modelling

We define attack surfaces, establish rules of engagement, and map your threat landscape to real adversary TTPs before a single packet is sent.

02

Reconnaissance & enumeration

OSINT, passive footprinting, and active discovery. We build a complete picture of your exposure — the same one your adversaries have.

03

Exploitation & lateral movement

Manual exploitation chained with privilege escalation and pivoting to demonstrate real business impact, not just CVSS scores.

04

Reporting & debrief

Executive and technical reports with risk-prioritised findings, proof-of-concept reproductions, and a remediation roadmap your team can act on.

05

Retest & verification

Retest of critical and high findings after remediation, so an engagement isn't considered closed until the vulnerabilities are gone.

// TRACK RECORD

Real engagements,
not just certifications.

01 - EXTERNAL PENTEST

Domain Admin via an external-only attack path

Achieved full domain compromise starting from an internet-facing foothold during a black-box network penetration test.

02 - INTERNAL / ON-SITE

Domain compromise aboard a cruise ship

Gained full domain control during an on-site internal penetration test, connecting directly into onboard network infrastructure.

03 - CAREER

6+ years across EY and NAB

Delivered penetration tests and red team assessments across banking, utilities, healthcare, and mining sectors, later leading group security and red team functions at NAB.

// CERTIFICATIONS

Certified, since 2016.

Some of these were issued several years ago and may be due for renewal — happy to confirm current status for any specific requirement.

Offensive Security

  • Offensive Security Certified Professional (OSCP)
    OffSec · Jan 2016 · ID OS-101-05210
  • CREST Registered Tester
    CREST · Jan 2018
  • Certified Red Team Operator (CRTO)
    Zero-Point Security · Apr 2021
  • Adversary Tactics: Red Team Operations
    SpecterOps · Mar 2021

Cloud

  • AWS Certified Cloud Practitioner
    AWS · Oct 2020 · ID 0QYDCYDJK1F11WK7
  • AWS Certified Solutions Architect – Associate
    AWS · Dec 2020 · ID K75DVZCLDNRQ1XSM

Systems & Infrastructure

  • Red Hat Certified System Administrator (RHCSA)
    Red Hat · Dec 2016 · ID 160-269-502
  • Red Hat Certified Engineer (RHCE)
    Red Hat · May 2017 · ID 160-269-502
  • Microsoft Certified Professional (MCP)
    Microsoft · Jun 2018 · ID G852-3846
  • Microsoft Certified Solutions Associate: Windows Server 2016
    Microsoft · Aug 2018 · ID G906-5122
  • Microsoft Certified Solutions Expert: Core Infrastructure (Securing Server 2016)
    Microsoft · Feb 2019 · ID H044-7766
SECURE

Got overflow work, or need
a pentest booked in fast?

Signed agreement, clear scope, and I can start within days — remote-first, with travel available Australia-wide.