NOOB2ROOT

Operator

About

I test web applications, APIs, cloud and Active Directory for a living, then work with the teams behind them to fix what I find. Red team and purple team, mostly.

I did not start here. I started on a hardware support desk in 2012, moved through university IT, and spent nearly three years in a SOC triaging alerts and running investigations. Learning to defend first changed how I attack: I already know what the person on the other end of the alert is going to see.

This is where the working notes go — CVE analysis, proof-of-concept write-ups, and the tools I build when something I need does not exist yet.

  1. Nov 2024 — Present

    Offensive Security Analyst

    Security assessments and penetration testing across web applications, APIs, cloud and on-prem infrastructure, mobile systems and source code review. Identify weaknesses and demonstrate real impact through exploitation. Red and purple team exercises.

  2. Apr 2022 — Nov 2024

    Cyber Security Analyst

    Security event monitoring, triage and escalation across internal and managed-service customers. Established source, scope and impact during investigations, and drove continuous improvement in SOC operations.

  3. Jun 2021 — Nov 2021

    Cyber Security Auditor

    Built risk assessment processes and documentation aligned to national security standards. Supported the lead assessor on audit reports and nonconformity follow-up, and ran audit programmes for PCI DSS and ISO 27001.

  4. Mar 2017 — Oct 2017

    IT Service Desk Advisor

  5. May 2012 — Jul 2014

    Client Support Technician

Employers withheld by choice. The work is the point; the logos aren't.