Background

Twenty years on the infrastructure side of the wire.

I didn't come into security through a bootcamp. I came in through two decades of running carrier-class voice and network infrastructure — which changes how I think about what's worth testing, and how an attacker would actually move once they're in.

Career signal path

2007 – 2010

Tier 2 Technical Support

Started at the front line of real-world network problems — troubleshooting connectivity, hardware, and infrastructure issues on live carrier networks.

2010 – Present

Senior Voice Engineer

Design, deployment, and maintenance of carrier-class voice and network infrastructure: Asterisk variants, Avaya, Kamailio and other proprietary carrier-class switches, Cisco networking equipment, a wide range of IP phone hardware, plus the Linux, Windows Server, and Active Directory environments underneath it all.

2022 – Present

In-House Penetration Tester

Formalized the shift toward security — running internal assessments and applying an infrastructure engineer's eye to finding what actually breaks, and why.

2023 – Present

eJPT Certified & Branching Into Web Application Security

Certified in 2023, and now expanding deliberately from network- and telecom-focused testing into web application security — documented publicly through the writeups on this site.


Why this niche

Most web application testers have never operated the infrastructure underneath the apps they're testing. I have — Asterisk and other VoIP platforms, Avaya and Kamailio deployments, carrier-class switching gear, Cisco networking, Windows and Linux servers, and Active Directory environments. That shows up in how I test: I don't just look for the vulnerability in the code, I think about what it means when that flaw meets a real network — where it pivots, what it exposes, and what an operator on the other end actually needs to hear to fix it.


Get in touch

Have a web app, network, or telecom/VoIP environment you'd like assessed? Reach out.