Independent Security Consultant

Clear findings.
Practical remediation.

ACyberSecure is my independent security practice. Before going independent, I personally delivered 300+ security projects and 125+ penetration testing engagements across in-house and consulting roles — cloud and M365 reviews, phishing work, and findings readouts for engineers and executives.

300+
Security Projects
125+
Pentest Engagements
5+
Years in Security
Tech + Exec
Findings Readouts

Projects delivered across in-house, consulting, and independent roles.

Scroll

Enterprise security experience, delivered by the engineer you hire

ACyberSecure is my independent consulting practice, focused on penetration testing, cloud and M365 reviews, gap assessments, phishing-related engagements, and security advisory. Before going independent, I delivered 300+ security projects and more than 125 penetration tests through in-house and consulting roles.

I've rebuilt report templates and assessment tooling over that time, which cut writing time and made findings easier to act on.

Direct engineer delivery

You work with me from scoping through readout — no sales handoff or account layers.

Practical scope

Penetration tests, cloud reviews, identity work, and advisory engagements are scoped to fit your budget, your deadline, and what your team can actually fix.

Clear stakeholder communication

Every report has a short executive summary and a technical section with reproduction steps and fixes, in that order.

Where I've done the work

Examples of organizations and environments I've worked within, through in-house and consulting engagements. The work has included internal and external penetration tests, cloud and M365 reviews, gap assessments, phishing-related work, and findings readouts.

Standards & Methods NIST CSF CIS Controls
Global Customer Experience (CX) Operations
30k+ staff, 20+ countries

Security work inside a global customer-experience organization.

Healthcare Payer Network
50M+ members

Assessments within a regulated payer environment.

Entertainment IP
$5B+ portfolio

Assessment work within a major content and IP portfolio.

Municipal Government
100k+ residents

Security work within public-sector operations.

Cold Chain Logistics
1B+ cu ft capacity

Reviews within temperature-controlled logistics operations.

Public Utility
10M+ people served

Security work supporting essential utility services.

Sizes are approximate and describe the organizations I worked within, not named clients — industry and scale only.

What I do

Penetration testing, continuous testing, red and purple teaming, gap assessments, cloud and identity reviews, and short implementation projects. I also run a small number of autonomous AI-driven penetration tests each year.

Continuous Pentesting

Recurring test cycles, retest support, and release validation to find regressions before release, on a cadence that matches your release cycle.

Discuss this service

Red & Purple Teaming

Scoped adversary emulation and collaborative exercises to test detection and response, including phishing and social engineering scenarios when appropriate.

Discuss this service

Gap Assessments (NIST/CIS)

Baseline your current state against NIST CSF or CIS Controls, then rank the gaps and give you a roadmap with separate technical and executive views.

Discuss this service

Cloud & M365 Security Audits

Azure, M365, and identity-focused reviews covering IAM, Entra ID, MFA, logging, admin risk, and control validation across cloud environments.

Discuss this service

Security Ops Support

Short-window support for Okta-to-Entra ID migration planning, licensing reviews, MFA and security configuration changes, endpoint security transitions, vulnerability triage, and related admin tasks.

Discuss this service

Credentials and deliverables

5+ years of hands-on security work in in-house and consulting roles, across penetration testing, cloud/M365 reviews, and security support.

Deliverables

  • Executive summary plus technical findings
  • Proof-of-concept steps and remediation guidance
  • Findings readout for technical and executive stakeholders
  • Optional retest validation support

Sample report available on request.

Credentials

CCSP (ISC2), eJPT, AZ-900, and SC-900.

CCSP eJPT AZ-900 SC-900

Public write-up

Public vulnerability research and coordinated disclosure notes from work I identified and reported, with direct links when there is a public technical write-up worth reading.

CVE Vikunja

CVE-2026-40103

Scoped API token authorization mismatch in Vikunja. The write-up documents the background-delete case I validated and the fix in 2.3.0.

Request Scope

If you need a pentest, cloud/M365 review, gap assessment, or short-window identity/security support, send a note with your environment, target scope, timing, and constraints. I'll follow up with next steps.

Typical response time: 1 business day.

Delivery

Remote-first, on-site by request

Availability

Flexible scheduling based on scope

Scope

Pentesting, cloud/M365, identity, advisory

Submitted details are used only to respond to your enquiry and processed by Netlify. See Privacy Policy.

Request Scope