I joined Secure Yeti as the 12th employee. It was a small team with no established infrastructure and lots of room to build.
My main duties are to lead and conduct penetration testing engagements. I have led 13 of the 24 engagements I participated in. During those we found 33 critical, 47 high, 43, medium, and 59 low vulnerabilities. Every vulnerability was written up in the context of NIST 800-53 REV 5 with PCI/DSS considerations for banking clients.
Other key projects I have led:
Multi-account AWS red team platform: Designed and implemented a NIST compliant red team platform that included IAM segmentation, cross-account networking, centralized security management. All deployed via Terraform and managed with Ansible.
Tabletop and IR playbook: I facilitated a 2-day tabletop with a regional health organization. Key leaders and security personnel attended to develop the companies first incident response playbook.