Zestysoft logo: a black stone Z repaired with gold kintsugi seams

Ian Brown · CISSP · OSCP

Independent security engineer.
I break things to make them stronger.

25+ years in security. Authorized penetration testing, detection engineering, and vulnerability research with responsible disclosure, backed by deep experience running real-world defense.

What I do

Blue team

Detection & response

  • SIEM architecture
  • Detection tuning
  • Increase visibility
  • AI-assisted triage and detections for insider threat and low-signal alerts
  • Incident investigation, root cause analysis, and threat hunting
  • Audit-ready controls for SOC 2, PCI DSS, ISO 27001, FedRAMP, HIPAA, NIST 800-53
Red team

Offensive testing

  • OSCP-certified penetration tester and vulnerability researcher
  • Software security assessments: cloud, web, and containers
  • Network penetration testing: internal and external
  • Binary analysis and reverse engineering
  • Threat modeling to turn findings into prioritized fixes

Services

Offense

Penetration testing

Scoped, authorized testing of cloud (AWS), web applications, containers, and internal or external networks. Clear findings with practical fixes.

Research

Bug bounty & disclosure

Vulnerability research under published program rules and safe-harbor terms. Findings are reported privately to the vendor first.

Researcher handle flatfoot on Bugcrowd and HackerOne
Defense

Detection engineering

SIEM and SOAR design, EDR tuning, high-signal detections, and AI-assisted triage that keeps analysts focused on real threats.

Assurance

Security program reviews

Threat modeling and control reviews mapped to SOC 2, PCI DSS, ISO 27001, FedRAMP, HIPAA, and NIST 800-53.

Track record

25+years in information security
50+log sources unified into one SIEM
90%drop in employee security mistakes after training
7branch offices secured end to end

Background spans fintech, legal technology, and insurance, from enterprise SOC leadership to sole security owner for a multi-site company.

Credentials

Certifications
  • CISSP · Certified Information Systems Security Professional (ISC2) · Verify →
  • OSCP · Offensive Security Certified Professional (OffSec) · Verify →
Education
  • Juris Doctor · Golden Gate University, San Francisco
  • B.S. Information Technology & Software Engineering · University of Phoenix

How I work

Offensive work happens only with written authorization and a defined scope, or under a published bug bounty policy. Vulnerabilities are reported privately to the owner first, with time to fix before any public discussion. Data seen during testing stays confidential. Every attack technique I learn becomes a detection I can write, and legal training keeps me careful about consent, privacy, and evidence.

Contact

For engagements or coordinated disclosure, reach me on LinkedIn. Code lives on GitHub. Bug bounty work is under the handle flatfoot on Bugcrowd and HackerOne.