Intersys.
Available for consulting

Intersys

Cybersecurity Professional CISSP Penetration Tester

Started in IT. Figured out the security problems were more interesting. Haven't looked back since.

CISSPCCSecurity+PenTest+CNVPCPT

About Me

Who I Am

IT background. Security focus. Genuinely curious about how things break.

I came up through IT and networking. Somewhere along the way I realized the more interesting question wasn't how to keep systems running. It was how someone would get in if they wanted to.

That shift led me to security full time, backed by a Master's from Trine University and a Bachelor's in Cyber Defense from Davenport University. I work across security architecture, penetration testing, and GRC, helping organizations understand their real exposure and not just their audit score.

$whoamiintersys

Master of Science in Information Studies

3.90 GPA

Trine University

Information Security & Technology Management

Bachelor of Science in Cyber Defense

3.97 GPA

Davenport University

Cyber Defense & Security Operations

My Approach

Proactive Defense

The best time to find a vulnerability is before someone else does. I lean into threat modeling and red-team thinking so organizations stop playing catch-up with adversaries.

Compliance Alignment

NIST and ISO 27001 aren't just there to make your auditor happy. They're blueprints for actually reducing risk. I help turn compliance requirements into controls that hold up in the real world.

Security Culture

You can have perfect tooling and still get phished by a fake invoice. Security culture is the layer that makes everything else work, starting with making sure every person in the org knows their role.

Areas of Expertise

What I Do

Deep technical knowledge paired with strategic thinking across the full security lifecycle.

Security Architecture

Designing layered, defense-in-depth security architectures that align with business objectives and scale with organizational growth.

Zero TrustSASEIAM

Penetration Testing

Conducting authorized offensive security assessments to identify vulnerabilities before malicious actors can exploit them.

Red TeamWeb AppNetwork

Compliance & GRC

Translating complex regulatory frameworks into actionable security programs that satisfy auditors and reduce real-world risk.

NIST CSFISO 27001SOC 2

AI/ML in Security

Applying machine learning techniques to threat detection, anomaly detection, and security automation while securing AI systems themselves.

Threat DetectionMLSecOpsLLM Security

Threat Intelligence

Collecting, analyzing, and operationalizing threat intelligence to inform defensive posture and proactive countermeasures.

CTIMITRE ATT&CKOSINT

Incident Response

Leading coordinated responses to security incidents — from initial detection through containment, eradication, and post-incident review.

DFIRPlaybooksRecovery

Credentials

Certifications

Validated expertise across security domains, governance, and offensive security practices.

CISSP

Certified Information Systems Security Professional

(ISC)²

CC

Certified in Cybersecurity

(ISC)²

Security+

CompTIA Security+

CompTIA

PenTest+

CompTIA PenTest+

CompTIA

CNVP

Certified Network Vulnerability Professional

CompTIA

CPT

Certified Penetration Tester

GAQM

IBM

IBM Cybersecurity Certification

IBM

Proofpoint

Proofpoint Security Certification

Proofpoint

XM Cyber

XM Cyber Attack Path Management

XM Cyber

9 active certifications across 5 issuing bodies

Projects

Built & Shipped

Practical tools built to demonstrate applied security concepts — not demos, actual things you can use.

Insights

Thoughts & Writing

Practical perspectives on security architecture, emerging threats, and building resilient programs.

Compliance & GRC

MFA Is Not the Finish Line

Enabling multi-factor authentication is one of the most effective controls you can deploy. It is also not nearly enough on its own, and attackers figured that out a while ago. Here's what MFA actually stops, what it doesn't, and what comes after.

Jun 1, 20265 min read
Read
Security Architecture

You Have 40,000 Vulnerabilities. Here's How to Care About the Right Ones.

The average enterprise vulnerability scanner returns tens of thousands of findings. Treating them all equally is operationally impossible and strategically wrong. Here's how to build a prioritization model that focuses your team on the vulnerabilities that are actually going to get you.

May 31, 20266 min read
Read
Penetration Testing

The Phishing Email That Got Past Me

I write phishing emails for a living. I've sent thousands of them to employees as part of authorized engagements. I know every trick in the playbook. And one got me anyway. Here's what happened and why it matters.

May 29, 20265 min read
Read
Security Architecture

Your Cloud Probably Has a Public S3 Bucket. You Just Don't Know About It Yet.

The most common finding in cloud security assessments isn't an exotic zero-day. It's a checkbox that defaulted to public, an IAM role that was supposed to be temporary, and a storage bucket named after an internal project sitting fully exposed to the internet.

May 28, 20266 min read
Read
Compliance & GRC

Security Awareness Training Doesn't Work. Here's What Does.

Every year, employees click through the compliance module. Every year, people still get phished. The annual training checkbox is not a security control. Here's what actually changes human behavior in ways that hold up under real attack conditions.

May 27, 20265 min read
Read
Compliance & GRC

Your Password Policy Is a Work of Fiction

Eight characters, one uppercase, one number, one symbol. Changed every 90 days. Completely useless. Here's why your password policy is training users to create worse passwords, and what to do instead.

May 25, 20266 min read
Read
Penetration Testing

I Walked Into Your Building With a Box of Donuts

Physical penetration testing is the part of security assessments nobody wants to think about because the findings are deeply embarrassing. A look at how alarmingly easy it is to walk past $2 million worth of security technology with a smile and a pastry.

May 23, 20265 min read
Read
Security Architecture

Zero Trust Architecture: Beyond the Buzzword

Zero Trust has become one of the most overused terms in enterprise security. Here's what it actually means and what it takes to implement it in a way that reduces real risk.

May 20, 20265 min read
Read
Security Architecture

Zero Trust in Practice: Building a Roadmap That Sticks

Most Zero Trust programs stall after the first phase. The reason is almost never technical. Here's how to build a roadmap that survives contact with your organization.

May 15, 20265 min read
Read
AI/ML Security

AI-Powered Threat Detection: Separating Signal from Noise

Machine learning in security operations creates as many false positives as it prevents. Here's how to tune your detection models and build analyst workflows that scale.

May 10, 20265 min read
Read
AI/ML Security

LLM Security: The Attack Surface No One's Ready For

Large language models introduce a new class of vulnerabilities that traditional security controls weren't designed to catch. Here's what security teams need to understand now.

May 5, 20265 min read
Read
Compliance & GRC

NIST CSF 2.0: What Changed and What It Means for Your Program

The updated framework introduces a new Govern function and expands scope beyond critical infrastructure. A practitioner's guide to mapping your existing controls to the new structure.

April 28, 20265 min read
Read
Penetration Testing

What Really Happens During a Penetration Test

A penetration test is not a vulnerability scan with a human attached. Here's what a real engagement looks like from scoping to final report and what separates useful findings from checkbox compliance.

April 20, 20265 min read
Read

Get In Touch

Let's Work Together

Available for consulting engagements, speaking opportunities, and strategic security advisory roles.

Whether you need a security architecture review, a penetration test scoped for your environment, or a keynote that makes compliance genuinely interesting — reach out and let's talk.