Offensive Security Specialist

Offensive security for critical infrastructure and high-trust environments.

OSCP+ offensive security professional with 6+ years at a critical infrastructure organization, specializing in penetration testing, red team operations, Active Directory attack paths, and security programs that scale.

6+Years Experience
OSCP+OffSec Certified
TVACritical Infrastructure
20+ hrsMonthly Labor Automated

About

Evidence-driven offensive security with executive-level communication.

I turn exploitation chains, assessment data, and operational findings into practical risk reduction. My background includes end-to-end red team and penetration testing work across network, web, social engineering, Active Directory, and post-exploitation scenarios.

At Tennessee Valley Authority, I have helped mature offensive security operations, social engineering, vulnerability disclosure, reporting, and security metrics programs. I also bring client-facing consulting experience from NetSPI.

Web Application Testing Network Penetration Testing Active Directory Executive Briefing

Experience

Professional background.

Enterprise offensive security experience in critical infrastructure, supported by consulting work across client environments.

Mar 2020 - Current

Specialist - Penetration Tester / Red Team

Tennessee Valley Authority, Chattanooga, TN. Executes red team and penetration testing engagements across network, web, social engineering, Active Directory, and post-exploitation scenarios while supporting leadership-level risk reduction decisions.

TVA
Sep 2022 - Dec 2022

Associate Security Consultant

NetSPI, Chattanooga, TN. Performed web application and network penetration tests using Burp Suite, CrackMapExec / NetExec, and Metasploit, delivering actionable findings that improved client security posture.

NetSPI

Expertise

Where I create value.

Practical offensive security capabilities backed by enterprise delivery, consulting experience, and leadership-ready reporting.

01

Penetration Testing

Network and web application assessments that move beyond tool output into exploitability, business impact, and practical remediation guidance.

02

Red Team Operations

Adversary emulation covering initial access, C2 infrastructure, lateral movement, post-exploitation, and OPSEC-aware execution.

03

Active Directory Attack Paths

Validation of credential abuse, Kerberoasting, privilege escalation, lateral movement, and domain compromise scenarios.

04

Social Engineering Programs

Development of repeatable phishing and human-risk assessment programs with methodology, metrics, reporting, and leadership-ready outcomes.

05

Security Program Maturity

Vulnerability disclosure operations, BAS validation, security metrics, executive reporting, and automation-backed analyst efficiency.

06

Red Team Infrastructure

C2 frameworks, redirectors, domain staging, payload delivery paths, traffic shaping, and operational infrastructure built with OPSEC in mind.

07

BAS and SIEM Validation

Breach and Attack Simulation exercises that test live detection logic, expose alerting gaps, and help defenders improve measurable coverage.

08

AI-Augmented Offensive Workflows

Responsible use of AI tooling to accelerate OSINT enrichment, tooling development, pretext ideation, and repeatable engagement workflows.

09

Executive Reporting

Translation of complex exploitation chains into concise business risk, remediation priorities, and leadership-ready security investment decisions.

Projects

Selected technical work.

A focused project section showing applied engineering, research, and communication beyond day-to-day employment.

Personal Research

Wireless SIGINT Tool

Python-based platform for capturing, correlating, and analyzing Bluetooth and Wi-Fi signals, with GPS mapping for passive device identification and movement-pattern analysis.

Security Education

Cybersecurity Cheatsheet

Interactive reference for offensive security commands, workflows, and field notes designed to make common assessment tasks faster and easier to recall.

View project
Senior Capstone

Missile Defense Agency Scheduling Application

Python-based smart scheduling application delivered to the Missile Defense Agency, including backend data storage, algorithm-driven scheduling, and technical documentation.

Certifications

Professional credentials.

Certifications focused on practical offensive security, assessment methodology, and vulnerability validation.

Education

Academic background.

Formal computer science education with a cybersecurity concentration.

Dec 2020

B.S. Cyber Security

University of Tennessee at Chattanooga. Computer Science: Cyber Security, GPA 3.52. NSA/DHS National Center of Academic Excellence in Cyber Defense.

Contact

Professional inquiries.

For offensive security, red team, application security, vulnerability research, or consulting discussions, contact me directly.