Security engineering · vulnerability research · offensive security

Security engineering · Vulnerability research · Offensive security · Automation

Enterprise security depth with an attacker's mindset.

Security engineering and vulnerability research grounded in real production environments, with practical offensive testing and custom automation.

I bring defender/operator context to assessment work: exploitability, evidence, production risk, and remediation.

Credibility strip

Apple product-security acknowledgementsValid vulnerability-report experience5+ years in regulated financial servicesThreat emulation and vulnerability assessmentCustom security tooling and automationExplorer Dates · 2.0k+ installs
Claims on this page come from the public author profile for @incredincomp and stay bounded to evidence represented there.

Focus

Security work for teams that need useful proof, not vague assurance.

Internal networks and identity

Enterprise network controls, Palo Alto, VPN, NAC, segmentation, Active Directory, Entra ID, Group Policy, Intune, and hybrid identity.

Application security and research

Burp Suite, OWASP testing concepts, authentication and access-control analysis, SAST/DAST, secure SDLC context, and responsible disclosure.

Assessment and custom tooling

Validate exploitability and controls with threat emulation, vulnerability assessment, and Python, PowerShell, Bash, and API-driven automation.

Capabilities

Selected capabilities

  • Palo Alto Networks, Panorama, Prisma Access, VPN, NAC, and segmentation
  • Active Directory, Entra ID, Group Policy, Intune, and hybrid identity
  • Burp Suite, OWASP, authentication, access control, SAST/DAST, and secure SDLC
  • Vulnerability assessment, threat emulation, and security-control validation
  • Azure, AWS, M365/Entra, Kubernetes, and cloud security posture
  • Custom security tooling in Python, PowerShell, Bash, and APIs

Selected work themes

Research, automation, and systemic-risk ownership.

Production security engineering

5+ years supporting regulated financial-services environments with distributed enterprise infrastructure and identity.

Vulnerability research and disclosure

Independent reporting with safe reproduction, impact boundaries, evidence, and remediation context.

Automation that extends assessment

Build repeatable collection, testing, and validation tools instead of relying solely on scanners.

Contact

Use this page as the public resume surface.

Appropriate for recruiting, security research follow-up, consulting fit checks, and product-security conversations.

Curated vulnerability intelligence and practical security automation by Incredincomp.