Offensive Security · Penetration Tester (Web & Network)
I break access controls, business logic, and SSRF, then write the report that fixes them.
Cybersecurity consultant (EY GDS) and penetration tester delivering network, web application, and AI security testing engagements. My working hours go to enterprise security operations and offensive engagements; my off-hours go to breaking web apps on bug bounty programs and publishing write-ups. The result: I attack with a defender's context and defend with an attacker's mindset.
🎯 Open to: remote penetration testing / offensive security roles (worldwide or EU-friendly)
🔬 Focus: broken access control & IDOR, business logic flaws, SSRF, and emerging AI/LLM & agent security
🧠 How I work: systematic and methodology-driven. Every finding ends in a clear impact statement and a remediation, not just a flag.
| Certification | Issuer | Status |
|---|---|---|
| PNPT — Practical Network Penetration Tester | TCM Security | ✅ Certified (2026) |
| CPTS — Certified Penetration Testing Specialist | Hack The Box | 🎯 Exam Sep 2026 |
| BSCP — Burp Suite Certified Practitioner | PortSwigger | 🎯 Exam Sep 2026 |
| Microsoft AI-900 · Zscaler ZDTE & ZDTA | Microsoft / Zscaler | ✅ Certified |
🔗 Verify: Credly · Hack The Box · PortSwigger
| Project | What it demonstrates |
|---|---|
| 🤖 AI Security Testing | AI/LLM penetration testing methodology, prompt injection, adversarial inputs, and agent security |
| 🛡️ Detection-as-Code Lab | 10 Sigma rules mapped to MITRE ATT&CK, translated to KQL and SPL, validated with synthetic telemetry, with analyst response playbooks |
| 🏠 Home SOC Lab | End-to-end Microsoft Sentinel SOC: Sysmon telemetry, KQL detection rules, Atomic Red Team validation, Logic Apps SOAR playbook, detection dashboard |
| 🏭 OT Security Assessment | Fictional IEC 62443 / NIS2 assessment for a municipal water utility: risk register, C2M2 maturity scorecard, remediation roadmap |
| 🗺️ Web App Pentest Methodology | End-to-end playbook: recon → enumeration → exploitation → reporting |
| ✍️ Security Write-ups | HTB machines & PortSwigger labs with full kill-chain, impact, and fix |
- Grinding CPTS (HTB Penetration Tester path) and BSCP, exams targeted September 2026
- Hunting public bug bounty programs and publishing sanitized findings
- Delivering AI/LLM security testing engagements and building methodology in this space
- Building out the AI Security Testing portfolio
- Learning Spanish 🇪🇸 (B1 target)
Everything here comes from authorized environments only: my own home lab, intentionally vulnerable training platforms (Hack The Box, PortSwigger), and public bug bounty programs tested strictly within scope and disclosure rules. No client data. No exploits against systems I don't own or have explicit permission to test. Findings against real programs are published only after remediation and in line with each program's policy.
LinkedIn: linkedin.com/in/matthewgcaballero Email: mattcaballero.work@gmail.com