A comprehensive record of my professional experience, certifications, security research, validated vulnerability disclosures, technical achievements, open-source contributions, and continuous learning throughout my cybersecurity career.
📥 Quick Curriculum Vitae Downloads
Whether you're recruiting for a specialist technical role or a leadership position, you can download the CV most relevant to your requirements.
🔴 Offensive Security | Red Team | Penetration Testing | Vulnerability Management
Designed for positions including:
- Red Team Operator
- Penetration Tester
- Application Security Engineer
- Offensive Security Consultant
- Vulnerability Management Lead
- Security Researcher
🔵 Cyber Defence | Architecture | Blue Team | Infrastructure
Designed for positions including:
- Network Architect
- Security Architect
- Infrastructure Architect
- Solutions Architect
- Security Operations
- Technical Lead
🟡 Cloud Security | DevSecOps | Software Engineering | Information Security
Designed for positions including:
- Cloud Security Engineer
- Cloud Architect
- DevSecOps Engineer
- Software Engineer
- Information Security Consultant
- Platform Security Engineer
👋 About Me
Availability: Available immediately for remote, hybrid and on-site work.
I am a cybersecurity professional with experience spanning offensive security, defensive security, cloud security, DevSecOps, application security, networking, software engineering, data science, and technical leadership.
This repository serves as a living technical curriculum vitae, documenting my continual professional development through:
- Industry-recognised certifications
- Practical security research
- Responsible vulnerability disclosure
- Bug bounty achievements
- Open-source development
- Security tooling
- Cloud engineering
- Programming
- Conference attendance
- Public speaking
- Professional publications
Rather than simply listing qualifications, this repository provides evidence of my technical progression and the practical application of my skills throughout my cybersecurity journey.
📍 Location
Ayr, Scotland, United Kingdom
Professional reference available from:
«This repository is organised into specialist domains including Offensive Security, Cyber Defence, Cloud & DevSecOps, Networking, Programming, Data Science, Governance, Technical Research, Open Source Projects, Industry Certifications, and Professional Achievements to make navigating my experience as straightforward as possible.»
💼 Professional Summary
A highly motivated and continuously developing cybersecurity professional with practical experience across Offensive Security, Application Security, Cloud Security, DevSecOps, Infrastructure Security, Network Security, Vulnerability Management, and Security Architecture.
My career has been built on combining technical research with hands-on experience, allowing me to identify, assess, prioritise, and remediate security vulnerabilities across modern enterprise environments.
I have experience conducting infrastructure, cloud, web application, API, and mobile security assessments while working with industry-standard security methodologies including the OWASP Top 10, MITRE ATT&CK, CVSS v3.1, SAST, DAST, SCA, container security, and secure software development practices.
Alongside professional development, I actively participate in bug bounty programmes, responsible vulnerability disclosure initiatives, security research, capture-the-flag platforms, laboratory environments, and open-source software development to continually expand my practical knowledge.
I enjoy building security tooling, automating security processes, researching emerging attack techniques, and sharing knowledge through publications, presentations, and community engagement.
I am seeking opportunities where I can contribute as a technical specialist, senior engineer, architect, or team leader while continuing to develop within Offensive Security, Cloud Security, Application Security, DevSecOps, and Security Architecture.
🎯 Core Areas of Expertise
- 🔴 Offensive Security & Red Teaming
- 🌐 Web & API Penetration Testing
- ☁ Cloud Security (AWS, Azure & Google Cloud)
- ⚙ DevSecOps & Secure SDLC
- 🛡️ Application Security
- 🔍 Vulnerability Assessment & Vulnerability Management
- 🧩 Security Architecture & Solution Design
- 🖥️ Infrastructure & Network Security
- 📱 Mobile Application Security
- 🧠 Threat Modelling & Risk Assessment
- 🔐 Identity, Access Management & Zero Trust
- 📊 Security Research & Responsible Disclosure
- 🤖 Security Automation & AI-Assisted Development
- 💻 Software Engineering & Open Source Development
🏆 Validated Security Research & Responsible Disclosure
Practical security research forms a significant part of my professional development.
The findings below represent validated vulnerabilities and recognised security contributions submitted through responsible disclosure and bug bounty programmes. They demonstrate practical application of offensive security techniques against real-world systems while following coordinated disclosure processes.
These acknowledgements complement my formal qualifications by providing independently validated evidence of technical capability.
Bug bounty Validations:
This section documents my industry-recognised certifications, professional qualifications, specialist training, and continuous professional development. Qualifications are grouped by technical discipline to provide a clearer overview of my capabilities across Offensive Security, Cyber Defence, Cloud Security, Networking, Software Engineering, Data Science, Governance, and emerging technologies.
Specialising in adversary simulation, penetration testing, vulnerability assessment, exploit development, web application security, operational security, threat emulation and security research.
Professional qualifications covering enterprise security, governance, defensive operations, application security and information security leadership.
Cloud architecture, secure infrastructure, Kubernetes, DevSecOps and enterprise platform security.
Enterprise networking, routing, switching, infrastructure security and network operations.
Programming languages, software engineering, automation and modern software development.
Languages and development technologies:
- Go
- Golang
- Ruby
- Serpent
- MPLS
- Full Stack Development
- Qualified Blockchain Developer
Machine Learning, Artificial Intelligence, Data Science and analytics.
Languages:
- R
- Rust
- C
- Python
- SQL
Professional development beyond purely technical disciplines.
(Further qualifications currently in progress.)
(Simplilearn)
My technical skillset spans offensive security, defensive security, cloud engineering, secure software development, infrastructure security, automation, and security operations.
- Advanced proficiency with:
- Kali Linux
- Parrot Security OS
- Windows Security Environments
- PowerShell
- Command Prompt
- Windows Subsystem for Linux (WSL)
- Ubuntu
- Kali NetHunter
Experienced deploying and operating security tooling across local, virtualised, mobile and remote environments.
- SAST (Static Application Security Testing)
- DAST (Dynamic Application Security Testing)
- SCA (Software Composition Analysis)
- Container Security Scanning
- Vulnerability Assessment & Management
- CVSS v3.x Risk Scoring
- OWASP Top 10 Testing
- API Security Testing
- Secure Software Development Lifecycle (SSDLC)
Experienced with vulnerability identification, prioritisation, remediation guidance and security improvement processes.
-
Virtualisation:
- VirtualBox
- VMware Workstation
-
Cloud Security:
- AWS Security
- Microsoft Azure Security
- Google Cloud Platform Security
-
DevSecOps:
- GitHub Security
- Azure DevOps Pipelines
- CI/CD Security Integration
- Repository Security Controls
- Firewall Administration and Management
- Security Architecture Reviews
- Technical Security Auditing
- Cryptography Fundamentals
- Security Automation
- Security Tool Development
- Full Environment Audits
- Section-Based Security Audits
@TheMadHattersPlayground
Remote
Duration: 1 year 6 months
Responsible for bridging offensive security testing with defensive security improvements through vulnerability discovery, risk assessment, remediation guidance and security architecture improvements.
-
Led infrastructure and application vulnerability assessments across security environments.
-
Managed vulnerability prioritisation and remediation processes.
-
Applied offensive security methodologies to identify weaknesses within applications and infrastructure.
-
Utilised SAST, DAST, SCA and container security scanning methodologies.
-
Implemented security improvements across GitHub repositories including:
- Repository security controls
- Licensing management
- Authentication security
- Secure development practices
-
Developed scripts and automation to improve security workflows.
-
Managed CVSS v3.x vulnerability ratings and risk prioritisation.
-
Conducted web application security assessments using industry-standard methodologies.
-
Performed OWASP Top 10 security testing.
-
Conducted application testing using tools including:
- Burp Suite Enterprise
- Veracode
-
Assisted with Web Application Firewall configuration and security improvements.
-
Supported Azure DevOps Pipeline security integration.
-
Progressed from entry-level VAPT assessment activities into a Purple Team Architect role combining offensive and defensive security responsibilities.
Participating platforms include:
- Meta
- Bugcrowd
- Integriti
- GitHub
- Remedy
- Zerodium
- ZeroDay Community
- Blockchair
- ZBD
- HackerOne
Hands-on security training completed through:
- Starting Point Path
- CREST Penetration Testing Path
- Heist Season (Started)
- Multiple security learning paths completed
- SOC Analyst Path
Completed:
- VulnHub
- DVWA
- OWASP Juice Shop
- crAPI
- vAPI
- Clickjacked
- Ransomware Defence
Completed:
- Red Team Boot Camp
- ARTO
- CyberBankSA Machine
- macOS X Machine
- #H4ck3d1t./exe
- TheMadHattersPlayground.com
- CyberShorts2024
- DeadmanXXXII
Projects include security research, software development, automation, cybersecurity education and technical experimentation.
Participated in security conferences, technical events and industry seminars including:
- Unplugged
- CWL
- Apollo HQ
- DEF CON
- Black Hat
- CALTECH
- APIsec University
- UK Cyber Convention
- Apollo R&D
- Apollo Business Continuity
Outside of cybersecurity, I have developed experience across multiple industries demonstrating adaptability, discipline and continuous professional development.
Delivered a demonstration focused on:
"The power of a smartphone in OSINT investigations."
Author of cybersecurity educational material available through online publishing platforms.
A practical cybersecurity guide covering foundational security concepts, bug bounty methodology, cloud security, network defence, virtual lab environments, vulnerability research and secure infrastructure design.
Available through:
A practical guide covering Open Source Intelligence (OSINT), reconnaissance techniques, information gathering methodologies, enumeration processes, digital footprint analysis and the foundations of ethical security research.
Designed for cybersecurity learners, security researchers and anyone developing practical skills in intelligence gathering and reconnaissance workflows.
Available through:
Before transitioning into cybersecurity, I developed practical experience across engineering, construction and hospitality environments.
Qualifications and experience include:
- Excavator Operator (CPCS)
- Lifting Operations (CPCS)
- Dump Truck Certification (CPCS)
- CISRS Scaffolding Qualifications
- Advanced Bricklaying
- Construction Foundation Work
- Michelin Star Chef Experience
- Professional fighter experience with Venum
- Competed in Super Showdown 2022, Brighton
















































