I didn't come into security through a bootcamp. I came in through two decades of running carrier-class voice and network infrastructure — which changes how I think about what's worth testing, and how an attacker would actually move once they're in.
Started at the front line of real-world network problems — troubleshooting connectivity, hardware, and infrastructure issues on live carrier networks.
Design, deployment, and maintenance of carrier-class voice and network infrastructure: Asterisk variants, Avaya, Kamailio and other proprietary carrier-class switches, Cisco networking equipment, a wide range of IP phone hardware, plus the Linux, Windows Server, and Active Directory environments underneath it all.
Formalized the shift toward security — running internal assessments and applying an infrastructure engineer's eye to finding what actually breaks, and why.
Certified in 2023, and now expanding deliberately from network- and telecom-focused testing into web application security — documented publicly through the writeups on this site.
Most web application testers have never operated the infrastructure underneath the apps they're testing. I have — Asterisk and other VoIP platforms, Avaya and Kamailio deployments, carrier-class switching gear, Cisco networking, Windows and Linux servers, and Active Directory environments. That shows up in how I test: I don't just look for the vulnerability in the code, I think about what it means when that flaw meets a real network — where it pivots, what it exposes, and what an operator on the other end actually needs to hear to fix it.
Have a web app, network, or telecom/VoIP environment you'd like assessed? Reach out.