I break into things for a living.
I’m the Head of Offensive Security at Xora (opens in new tab). We build autonomous penetration testing for modern software teams. I’ve spent the last decade testing systems, leading teams, and figuring out how organizations fail at security—and how to do something useful about it.
Before that, I worked red team operations at Bishop Fox and spent five years at risk3sixty, where I led the penetration testing practice. I publish security writing here and through Empiric Security (opens in new tab), my independent consulting outfit.
Recent Writing
- Everyone Has A Plan Until They Get Punched In The SonicWall Why any organization with a public IP has to plan for un-patchable zero-day exploitation, not just targeted attacks.
- You Can't Just Publish Partial Exploits Anymore Now published at Xora: taking a 'safely' disclosed WordPress RCE most of the way to a full unauthenticated exploit chain with public research and an LLM.
- One Home for Everything I Write Consolidating my scattered writing under one roof, without giving up digital ownership.
I post new writing here first. Follow a feed to catch it as it goes up. I ♥ RSS (opens in new tab)
Photos

Outside of work, I shoot film (opens in new tab) and ride motorcycles. More frames are over here (opens in new tab).