Ian Brown · CISSP · OSCP
Independent security engineer.
I break things to make them stronger.
25+ years in security. Authorized penetration testing, detection engineering, and vulnerability research with responsible disclosure, backed by deep experience running real-world defense.
What I do
Detection & response
- SIEM architecture
- Detection tuning
- Increase visibility
- AI-assisted triage and detections for insider threat and low-signal alerts
- Incident investigation, root cause analysis, and threat hunting
- Audit-ready controls for SOC 2, PCI DSS, ISO 27001, FedRAMP, HIPAA, NIST 800-53
Offensive testing
- OSCP-certified penetration tester and vulnerability researcher
- Software security assessments: cloud, web, and containers
- Network penetration testing: internal and external
- Binary analysis and reverse engineering
- Threat modeling to turn findings into prioritized fixes
Services
Penetration testing
Scoped, authorized testing of cloud (AWS), web applications, containers, and internal or external networks. Clear findings with practical fixes.
Bug bounty & disclosure
Vulnerability research under published program rules and safe-harbor terms. Findings are reported privately to the vendor first.
Researcher handleflatfoot on
Bugcrowd and
HackerOne
Detection engineering
SIEM and SOAR design, EDR tuning, high-signal detections, and AI-assisted triage that keeps analysts focused on real threats.
Security program reviews
Threat modeling and control reviews mapped to SOC 2, PCI DSS, ISO 27001, FedRAMP, HIPAA, and NIST 800-53.
Track record
Background spans fintech, legal technology, and insurance, from enterprise SOC leadership to sole security owner for a multi-site company.
Credentials
How I work
Offensive work happens only with written authorization and a defined scope, or under a published bug bounty policy. Vulnerabilities are reported privately to the owner first, with time to fix before any public discussion. Data seen during testing stays confidential. Every attack technique I learn becomes a detection I can write, and legal training keeps me careful about consent, privacy, and evidence.
Contact
For engagements or coordinated disclosure, reach me on LinkedIn. Code lives on GitHub. Bug bounty work is under the handle flatfoot on Bugcrowd and HackerOne.