ABOUT

One tester.
Real, verifiable
track record.

HexCipher Security is an independent penetration testing practice based in Melbourne, Australia — built on hands-on experience across consultancy, in-house, and founder roles, not a large team or a sales pitch.

I've spent the last several years moving between consultancy, in-house, and founder roles in security — which means I've seen how the same finding looks from a client's side, an internal security team's side, and an engineering team's side.

Right now I'm mainly looking to take on overflow and subcontract work for consultancies with more demand than bench capacity — sign an agreement, agree scope and rate, and start quickly, remote-first, with travel available anywhere in Australia if an engagement needs it.

HexCipher Security operates under a PTY LTD, and carries AUD $5,000,000 professional indemnity and liability insurance per claim — that figure can be increased for engagements that require higher cover.

// BACKGROUND

Career timeline

EY

Penetration Tester / Consultant

Delivered network, application, and red team assessments across banking, utilities, healthcare, and mining clients.

NAB

Principal, Group Security → Principal, Red Team

Led an internal security assessment function, then moved into leading NAB's red team practice.

INDEPENDENT

Contract & Overflow Penetration Testing

Delivering contract penetration testing engagements while building out HexCipher Security.

// NOTABLE WORK

A couple of things
worth mentioning.

01 - EXTERNAL PENTEST

Domain Admin via an external-only attack path

Achieved full domain compromise starting from an internet-facing foothold during a black-box network penetration test.

02 - INTERNAL / ON-SITE

Domain compromise aboard a cruise ship

Gained full domain control during an on-site internal penetration test, connecting directly into onboard network infrastructure.

// CERTIFICATIONS

Certified, since 2016.

Some of these were issued several years ago and may be due for renewal — happy to confirm current status for any specific requirement.

Offensive Security

  • Offensive Security Certified Professional (OSCP)
    OffSec · Jan 2016 · ID OS-101-05210
  • CREST Registered Tester
    CREST · Jan 2018
  • Certified Red Team Operator (CRTO)
    Zero-Point Security · Apr 2021
  • Adversary Tactics: Red Team Operations
    SpecterOps · Mar 2021

Cloud

  • AWS Certified Cloud Practitioner
    AWS · Oct 2020 · ID 0QYDCYDJK1F11WK7
  • AWS Certified Solutions Architect – Associate
    AWS · Dec 2020 · ID K75DVZCLDNRQ1XSM

Systems & Infrastructure

  • Red Hat Certified System Administrator (RHCSA)
    Red Hat · Dec 2016 · ID 160-269-502
  • Red Hat Certified Engineer (RHCE)
    Red Hat · May 2017 · ID 160-269-502
  • Microsoft Certified Professional (MCP)
    Microsoft · Jun 2018 · ID G852-3846
  • Microsoft Certified Solutions Associate: Windows Server 2016
    Microsoft · Aug 2018 · ID G906-5122
  • Microsoft Certified Solutions Expert: Core Infrastructure (Securing Server 2016)
    Microsoft · Feb 2019 · ID H044-7766
ABOUT

Have overflow work,
or want to talk scope?

Signed agreement, clear scope, and I can start within days — remote-first, with travel available Australia-wide.