Riley Park Senior Penetration Tester
Seattle, WA • pentester@gmail.com • +1 206-555-0177
Profile Summary
- Senior Penetration Tester with 7 years of experience running offensive security consulting engagements across fintech, SaaS, and federal contractor environments, specializing in red team operations, web application testing, and Active Directory exploitation.
- Hands-on coverage across reconnaissance (Amass), vulnerability scanners (Burp Suite Pro, Nessus), C2 frameworks (Cobalt Strike, Sliver), AD exploitation (BloodHound, Mimikatz), and scripting (Python, PowerShell) with strong fundamentals in MITRE ATT&CK mapping, OPSEC discipline, and audit-ready engagement reporting.
- Deep expertise in objective-based red team operations, TTP-driven adversary emulation, manual exploitation rigor beyond scanner output, and stealth and OPSEC discipline, leveraging methodologies such as MITRE ATT&CK-aligned engagement plans and purple-team debrief cycles to drive findings that map to real business risk and drive measurable security improvements.
- Engaged collaborator working closely with client blue teams, Detection Engineering, and AppSec partners in PTES- and OSSTMM-aligned engagements, contributing to scoping calls, retest cycles, and purple-team debriefs with a calm, evidence-first temperament.
- Emerging leader who shares technical excellence and fosters a culture of report clarity and reproducible proof-of-exploit through peer report reviews and tooling sessions, while leading internal red-team craft sessions and authoring widely used playbook and report templates.
Technical Skills
- Recon & OSINT:
- Amass, Subfinder, Recon-ng, Maltego, theHarvester, Shodan, Censys, GitHub dorking
- Web App & API Testing:
- Burp Suite Pro, OWASP ZAP, Caido, sqlmap, ffuf, dirsearch, OWASP Top 10, API pentest
- Network & AD Pentest:
- Nessus, Nmap, Impacket, NetExec (CrackMapExec), Responder, BloodHound, Rubeus, Kerberoasting
- Cloud & Mobile Testing:
- Pacu, ScoutSuite, Prowler, CloudGoat, MobSF, Frida, Objection, AWS / Azure / GCP IAM
- C2 & Exploit Frameworks:
- Cobalt Strike, Sliver, Mythic, Havoc, Metasploit, Brute Ratel C4 (familiarity)
- Post-Exploitation & Evasion:
- Mimikatz, Rubeus, SharpHound, Certify, Seatbelt, Process Hollowing, AMSI/ETW bypass
- Frameworks & Methodology:
- MITRE ATT&CK, OWASP WSTG, PTES, NIST 800-115, OSSTMM, CVSS v3.1, OSCP, OSEP
- Languages & Scripting:
- Python, PowerShell, C#, Go, Bash, Ruby, x86/x64 assembly (basic)
Education
Work Experience
- Led red team and adversary-emulation engagements for Fortune 500 and high-growth SaaS clients across 3- to 12-week runs covering internal Active Directory, external infrastructure, and cloud and web surfaces, delivering 40+ full-scope engagements.
- Drove web application and API penetration testing across 60+ assessments on Burp Suite Pro, working the full OWASP Top 10 alongside SSRF, IDOR, and business-logic chains with authenticated and unauthenticated Burp scans backed by manual review, delivering 180+ confirmed high or critical findings.
- Owned internal network and Active Directory penetration testing using BloodHound, Mimikatz, and Impacket to execute Kerberoasting and AS-REP roasting, attack-path analysis, and NTLM relay and coerced auth, compromising the domain on 22 of 25 internal engagements.
- Built reconnaissance and OSINT-driven attack-surface mapping on Amass and Shodan, running DNS and subdomain enumeration at scale alongside leaked-credential pivoting through public dumps and employee profiling, surfacing shadow IT and forgotten assets in 70% of external engagements.
- Executed post-exploitation, lateral movement, and privilege escalation through Mimikatz credential extraction, Golden and Silver Ticket forging, and pivoting through tiered admin networks, reaching crown-jewel data stores in 18 engagements.
- Stood up command-and-control infrastructure on Cobalt Strike with malleable C2 profiles plus Sliver for OPSEC-sensitive operations, shipping custom Python and C# loaders with AMSI and ETW bypass and evading CrowdStrike and SentinelOne EDR detection on 14 engagements.
- Delivered cloud, mobile, and specialized assessments across AWS, Azure, and GCP estates, exercising IAM privilege escalation, S3 and blob misconfiguration hunting, and metadata service abuse, closing the year with 14 cloud and 6 mobile assessments delivered.
- Ran vulnerability assessment and safe-exploitation engagements across 90+ assessments, combining Nessus and Nuclei automated scanning with manual validation and safe exploitation to demonstrate real impact, delivering 220+ validated vulnerabilities with CVSS-scored impact.
- Designed and executed social-engineering and phishing campaigns across 16 multi-channel programs including phishing email crafting with custom infrastructure and vishing and pretexting call scripts, achieving 28% click and 14% credential capture across the program.
- Authored client engagement reports and remediation guidance with executive summaries, CVSS-scored technical detail, proof-of-exploit screenshots, and prioritized remediation roadmaps, partnering with client AppSec, IT, and Detection Engineering across 22 client engagements; validated fixes through retesting on 60+ high/critical findings and onboarded 3 junior pentesters.