Cody M.
Lead Penetration Tester (Core Team Contractor) @ Cobalt
About
Senior penetration tester and red team operator specializing in web applications, Active Directory environments, and cloud infrastructure across Microsoft Azure and AWS. I have delivered 50+ penetration testing and adversary simulation engagements across enterprise and mid-sized environments, including web applications, APIs, internal networks, and cloud identity platforms. My work focuses on realistic attack paths, exploit chain validation, and practical remediation guidance that small and mid-size organizations can operationalize quickly. Highlights: • 8 MITRE-assigned CVEs across Cisco, Brocade, and enterprise platforms • OSCP, CRTP, CARTP certified • Active Directory privilege escalation, NTLM relay, Kerberos abuse, ADCS misconfiguration • Cloud compromise paths across Azure, Entra ID, and AWS • Executive and technical reporting aligned to NIST, OWASP, PTES, ISO, PCI, CMMC I work best with organizations that need clear risk articulation, defensible findings, and actionable remediation without unnecessary complexity.
United States
Columbia
Computer & Network Security
CMMC, SOC 2, NIST, Exploit Development, CVE Research, MITRE ATT&CK, Entra ID / Azure AD, AWS Security, Cloud Security (Azure), Internal Network Penetration Testing, Active Directory Security, Product Security, DevSecOps, Red Teaming, OWASP, Project Scope Development, Mentoring, Technical Writing, Penetration Testing, Cloud Security
Experience

Lead Penetration Tester (Core Team Contractor)
• Delivered 20+ PTaaS engagements across web applications, APIs, internal Active Directory, and Azure/AWS cloud environments • Identified privilege escalation chains, domain compromise paths, and cloud identity abuse scenario • Validated exploit chains and severity ratings to ensure defensible risk scoring • Partnered directly with client security teams to scope engagements and translate findings into remediation roadmaps • Produced executive-ready and deeply technical reports aligned to OWASP and MITRE ATT&CK

Offensive Security Architect / Security Researcher
• Designed red team and penetration testing engagements across enterprise, cloud, XIoT, and application environments • Built structured adversary simulations including initial access, privilege escalation, persistence, and data exfiltration scenarios • Conducted large-scale external reconnaissance and attack surface enumeration • Delivered executive-level attack narratives and technical post-assessment briefings • Contributed to offensive methodology refinement and service delivery improvements

Offensive Security Architect / Security Researcher
Seattle, Washington, United States
• Scoped and architected penetration testing and adversary simulation engagements • Built automation tooling in Python and C# to streamline reporting and engagement workflows • Contributed research to the App Defense Alliance under the Linux Foundation • Authored detailed SOWs defining attack surfaces, threat models, and rules of engagement • Developed internal reporting pipelines to normalize findings and improve consistency

Senior Red Team Operator
Charleston, South Carolina Metropolitan Area
• Executed 30+ full-scope penetration tests and red team engagements • Achieved domain compromise through phishing-based initial access and Active Directory privilege escalation • Designed and operated C2 infrastructure, redirectors, and evasive payload delivery mechanisms • Published 8 MITRE-assigned CVEs affecting enterprise XIoT devices • Contributed exploit modules and proof-of-concepts to the Metasploit Framework • Delivered reporting aligned to NIST SP 800-30 and CMMC frameworks • Mentored junior operators in AD exploitation, cloud attack paths, and web application testing

Software Development Intern
Mobile, Alabama Area
• Designed and developed custom application for business operations using C# and JavaScript • Increased the speed of product development by coordinating team resources more effectively • Performed code reviews regularly • Delivered the product on time and meeting all customer requirements.

Software Development Intern
Mobile, Alabama Area
- Designed and developed multiple custom applications for external and internal corporate functions using C# and JavaScript - Managed front-end and server-side application development - Performed code reviews regularly - Worked with the client to ascertain product functional requirements - Delivered fully functioning products to client on time that met all requirements
Education
Cody M.'s Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.



