Find what attackers would, before they do.
Independent penetration testing and security consulting for small businesses and industrial operations, by a working IT/OT security engineer. Based in Lafayette, Louisiana — available nationwide.
Most breaches don't start with a genius exploit.
They start with something ordinary, a forgotten server, a reused password, a default nobody changed. My job is to find yours first.
Security Services
Focused engagements scoped to what you actually need, no bloated retainers, no scanner output dressed up as a penetration test.
Penetration Testing
Internal and external network testing to identify weaknesses before attackers exploit them.
Learn more →Web Application Testing
OWASP-aligned testing of your web applications for authentication, access control, and business logic flaws.
Learn more →Vulnerability Assessment
Systematic identification and prioritization of security weaknesses across your environment.
Learn more →Wireless Penetration Testing
Assessment of your Wi-Fi infrastructure for weak encryption, rogue access points, and segmentation gaps.
Learn more →OT/ICS Security Assessment
Safety-first security assessments for operational technology and industrial control environments.
Learn more →Security Consulting
Guidance on security architecture, policy development, and building a defensible security program.
Learn more →A clear engagement, end to end
No mystery, no surprises. You know exactly what happens at every stage, and where you sign off.
Scope
We define what's in bounds, your goals, and any operational constraints. For OT and production systems, safety and uptime come first.
Test
Hands-on testing the way a real attacker works. Findings are exploited and verified manually, proof of impact, not just a scanner flag.
Report
A prioritized report with clear remediation steps and proof of impact, written to be acted on, not a 200-page scanner dump.
Retest
Once your team has remediated, I re-verify the fixes so you can prove the issues are actually closed.
Scoped to your environment, not a price list
Every engagement is quoted after a short scoping conversation, so you only pay for the work your environment actually needs. A few things shape the number:
Scope & size
How much is in bounds, a single application versus your whole network and everything on it.
Number of targets
How many hosts, applications, sites, or devices fall inside the agreed scope.
Environment complexity
Standard IT versus OT/ICS and production systems, which need extra, safety-first care.
Depth & retest
How deep the testing goes, and whether you want a retest to verify your fixes.
Why Work With Me
A working practitioner, not a detached consultant, you get the person doing the testing.
A Working Practitioner
I work daily as a cybersecurity engineer across enterprise IT and OT, the same kinds of systems I'll be testing for you, not theory from a slide deck.
Manual, Not Just Scanned
I exploit findings by hand to prove real-world impact, not just flag what a scanner noticed. Modern tooling helps me move faster, the judgment and accountability stay human.
A Real Attacker's Mindset
Active bug bounty researcher with credited findings, including a critical-severity issue in a widely used enterprise product. I find what scanners and checklists miss.
Reports You Can Act On
Prioritized findings, proof of impact, and remediation steps your team can actually implement, not a 200-page dump of raw scanner output.
Real-World MSP Experience
A prior background across 30+ MSP engagements means I understand real budget constraints, mixed environments, and the compliance pressure you're under.
Direct Access
You work directly with the person doing the testing. No account managers, no handoffs, no junior quietly doing the real work.
Ready to scope a test?
Tell me what you're protecting — I'll tell you what I'd test and what it costs. No pressure, no retainer pitch.
Sample Work
Internal Network Penetration Test
Multi-vector attack chain demonstrating lateral movement and domain compromise.
View ReportMalware Analysis Report
Analysis of multi-stage malware including macro document, dropper, and exfiltration payload.
View ReportBug Bounty Findings
Credited vulnerability research across public programs, including a critical-severity finding currently under non-disclosure.
HackerOne profileFrequently Asked Questions
How long does a penetration test take?
Will testing disrupt my operations?
Is the testing automated or manual?
Do you offer retests after we remediate?
What size and type of businesses do you work with?
Contact
Ready to find out what attackers would find?
Let's discuss your security needs and how a penetration test can help protect your business. I personally read and respond to every inquiry within one business day.