root@mstringer:~$

Michael Stringer

Information Security Executive / Offensive Security Strategist / AI Security Leader

15+ years bridging offensive security, executive strategy, and hands-on engineering across SaaS, consulting, and enterprise environments. Built a $6.6M/yr offensive practice from scratch. Currently leading enterprise security at AppOmni — SOC 2, secure SDLC, AI security, and the customer trust program that accelerates sales cycles.

  • CISSP
  • OSCP
  • OSWP
  • CEH
Location
Cleveland, OH
Availability
Remote U.S. & Canada · ET/CT/PT
Focus
vCISO · Red Team · AI Security
01

Professional Summary

Equally comfortable briefing a board on risk posture, hardening Kubernetes workloads with Terraform, leading adversarial AI assessments against production LLMs, or running a Fortune 500 red team that closes a $2M renewal. Author of The Hacker Ethos, CVE researcher, and recurring conference speaker.

Security Leadership & Strategy

Multi-year roadmaps, board & exec communication, P&L ownership, team building, customer trust programs, due diligence support, security as a revenue enabler.

Offensive Security & Red Teaming

Adversary emulation, APT simulation, MITRE ATT&CK operations, purple teaming, exploit development, vulnerability research, social engineering, custom C2.

AI / LLM Security

LLM threat modeling, prompt injection testing, adversarial AI assessments, AI guardrail validation, MITRE ATLAS, OWASP Top 10 for LLMs, secure AI deployment.

Governance, Risk & Compliance

SOC 2 Type II ownership, FedRAMP, ISO 27001/27002, NIST CSF, NIST SP 800-53, PCI DSS 4.0, HIPAA, HITRUST, GDPR, FISMA.

Cloud Security & IaC

AWS, GCP, Azure; Kubernetes (EKS/GKE/AKS); Terraform; zero-trust architecture; CSPM; secrets management.

Detection & Response

SIEM design & tuning, EDR/XDR, detection engineering, incident response, threat hunting, BCDR planning.

02

Experience

  1. Feb 2025 — Present · Remote

    Lead Security Engineer, Enterprise Security

    AppOmni Inc

    SaaS security platform protecting enterprise SaaS deployments across Salesforce, Microsoft 365, ServiceNow, and others.

    • Established the enterprise security function from the ground up; defined the long-term roadmap, control maturity targets, and operating model presented quarterly to executive leadership.
    • Own the SOC 2 Type II program end-to-end — control design, evidence automation, audit coordination, ongoing stewardship; reduced audit prep overhead by ~30%.
    • Designed security controls and SOPs for 1,500+ cloud resources, cutting misconfigurations by 40%.
    • Architected zero-trust workstation isolation, achieving 80% reduction in lateral-movement attack surface.
    • Lead AI security for AppOmni's "AskOmni" AI Agent — LLM threat modeling, prompt injection testing, adversarial AI assessments, guardrail validation.
    • Built and operate the customer trust program (questionnaires, due diligence, customer briefings), improving response efficiency >25% and accelerating sales cycles.
    • Drove secure SDLC adoption across all product teams, reaching 85%+ developer adoption.
    • Built automated assessment & reporting pipelines — 22% reduction in time-to-delivery, >40% faster critical remediation.
    • Influenced flagship product posture, contributing to $60M+ ARR through secure product design and customer-facing security capabilities.
  2. Oct 2017 — Jan 2025 · Remote

    Principal Information Security Consultant, Lead Penetration Tester

    Online Business Systems

    ~800-person technology and consulting firm across North America.

    • Built and led the Offensive Security Services (OSS) practice from inception — scaled to a 15-person global team representing 2% of headcount while delivering 14% of annual realized revenue.
    • Grew practice revenue to $6.6M+ annually across 250+ engagements; drove $5M in gross revenue growth and a 150% profit-margin increase over three years.
    • Owned full P&L — pricing, capacity planning, vendor selection, hiring, career ladders, KPI frameworks.
    • Designed and executed red team operations and APT simulations for Fortune 500 clients; one engagement directly contributed to a $2M contract renewal.
    • Created a social engineering / spear-phishing service line generating $300K in new annual revenue.
    • Translated adversary findings into executive roadmaps and SSDLC changes with measurable, tracked risk reduction.
    • Conducted compliance-driven assessments across NIST SP 800-53, PCI DSS 4.0, HIPAA, HITRUST, SOC 2, ISO 27001/27002.
    • Migrated OSS infrastructure to AWS with Terraform-managed IaC, VPC segmentation, IAM hardening, CI/CD automation; deployed K8s assessment infrastructure.
    • Introduced AI-augmented testing (Horizon3.ai NodeZero) and automated reporting — 25% less assessment time, 80% faster delivery, $250K annual cost reduction.
    • Authored playbooks, training, and methodology adopted across the practice; mentored senior engineers into team leads.
  3. Jul 2018 — Nov 2023 · Remote · Concurrent

    CISO / Director of Security Services

    Nemesis Security Group

    • Owned the multi-year roadmap mapped to business OKRs; stood up the risk register, treatment plans, and quarterly executive reviews.
    • Established control framework alignment across SOC 2, ISO 27001/27002, NIST CSF, PCI DSS, HIPAA, FISMA with full policy library and maturity metrics.
    • Coordinated third-party audits and customer trust reviews with zero critical findings; centralized evidence streamlined prep by 25%+.
    • Designed cloud and on-prem architectures across AWS, Azure, GCP — IAM controls, logging/telemetry, zero-trust patterns.
    • Built detection/response runbooks, vulnerability SLAs, and purple-team exercises — >40% improvement in critical patch deployment timelines.
    • Launched a security champions program and BCDR tabletops; elevated secure coding adoption across >80% of dev teams.
  4. Dec 2018 — Oct 2021 · Cleveland, OH · Concurrent

    Chief Information Security Officer (Fractional)

    Mechanical Piping Systems Inc

    • Defined data protection strategy, risk program, and baseline compliance posture from scratch; instituted asset classification and change control.
    • Architected secure network segmentation, Zero Trust access, email/web security, endpoint controls, and centralized logging.
    • Implemented DLP, MFA, least-privilege IAM, continuous patching, and IR playbooks & tabletops.
  5. Jan 2017 — Sep 2018 · Bedford, OH

    Senior Information Security Research Analyst

    SecureState (acquired by RSM US LLP)

    • Advanced vulnerability research, exploit development, and red team ops; co-discovered and disclosed CVE-2017-9770 and CVE-2017-9769 (Razer rzpnk.sys local privilege escalation).
    • Co-developed King Phisher, an open-source phishing & adversary simulation platform widely adopted across the security community.
    • Subject Matter Expert for Vulnerability Management service line responsible for $2.5M+ annual revenue.
    • Led PCI DSS Requirement 11 penetration testing & scan services across the client portfolio.
    • Contributed to technical marketing and BD — 40+ new client leads in a single year.
  6. Jul 2016 — Jan 2017 · Mentor, OH

    Senior Network Security Engineer

    Cornerstone IT

    • Designed, built, and maintained the AlienVault SIEM for SOC 2-compliant managed security services — correlation rules and alert tuning.
    • Developed the firm's DFIR methodology and ransomware response procedures; led recovery for 10+ clients during the Osiris/Odin epidemic.
    • Automated backup, recovery, and infra workflows via Datto — 45% improvement in containment and recovery times.
  7. 2009 — 2016 · Cleveland, OH

    Founder & Principal Consultant

    Elec-Techs IT Solutions

    Founded and operated an independent IT and network security consultancy serving enterprise, education, manufacturing, and SMB clients across NE Ohio.

    • Lubrizol Corporation (via KForce): managed Cisco Nexus switch infrastructure across multiple NE Ohio facilities; remediated a total network-blackout event at the Wickliffe HQ campus.
    • Monreal LLC: Cisco CCNA-level infrastructure management supporting a gross annual revenue stream of $800K.
    • Cardinal Local School District: designed and deployed Windows Active Directory replacing aging Novell systems.
    • Cleveland Charter School District: introduced vulnerability management, patch management, and ticketing systems.
    • Windows/Linux admin, network architecture, malware analysis, DFIR, custom tooling in C/C++, Python, Ruby.
  8. Jun 2009 — Jul 2015

    Supply Specialist (E-4), Acting Supply Sergeant (92Y)

    United States Army Reserve

    Served with the 12/100th Battalion Reserve Regiment in support of operations in Afghanistan and Iraq. Honor Student, NCO Academy. Expert rifle marksmanship; top 90th percentile physical fitness.

03

Publications & Research

Book

The Hacker Ethos

The Beginner's Guide to Ethical Hacking

Author. A foundational text introducing newcomers to the discipline, methodology, and ethics of professional offensive security.

CVE

CVE-2017-9770

Local privilege escalation in Razer rzpnk.sys IOCTL driver process (co-discoverer / discloser).

CVE

CVE-2017-9769

Local privilege escalation in Razer rzpnk.sys IOCTL driver process (co-discoverer / discloser).

Open Source

King Phisher

Co-developer. Open-source phishing & adversary simulation platform written in Python, widely adopted across the security community for phishing assessments and awareness testing.

04

Credentials & Certifications

CISSP

Certified Information Systems Security Professional

#1940868

OSCP

Offensive Security Certified Professional

OS-101-049615

OSWP

Offensive Security Wireless Professional

OS-BWA-017030

CEH

Certified Ethical Hacker

ECC64427862880

Education

B.S. Computer Science, Information Technology

University of Phoenix · Summa Cum Laude (GPA 3.86) · Top 5 of graduating class

Member, Epsilon Pi Tau International Honor Society of Technology · Concentration: Information Assurance, Cybersecurity

Professional Certificate, Information Assurance & Security

University of Phoenix

05

Speaking Engagements

  • BSides Las Vegas · Portland · Cleveland · San Diego

    License to Pwn: How Two Muppets Compromised a Fortune 500 in < 6 Hours ↗

    A red team narrative on the operational reality of full-scope adversary simulation against a Fortune 500 target — chained social engineering, infrastructure compromise, and detection evasion delivered as an executive-grade case study.

  • 2023 GrrCon · Red Team Village

    GrrCon 2023 — Red Team Village

    Speaker, Red Team Village.

  • 2018 BSides Cleveland

    Raindance: Raining Recon From The Microsoft Cloud ↗

    Offensive reconnaissance techniques against Microsoft cloud services — enumerating tenants, users, and exposed surface area to inform red team operations and adversary simulation against Microsoft-centric enterprises.

  • 2018 DerbyCon

    DerbyCon 2018 — Presenter

    Presenter at one of the most influential community-driven security conferences of its era.

06

Technical Skills

Cloud & Infrastructure

  • AWS
  • GCP
  • Azure
  • EC2
  • VPC
  • IAM
  • S3
  • KMS
  • CloudTrail
  • GuardDuty
  • Security Hub
  • Kubernetes (EKS/GKE/AKS)
  • Docker
  • Helm
  • Terraform
  • Ansible

Security Engineering

  • Zero Trust
  • IAM design
  • Secrets management
  • Encryption at rest & in transit
  • CSPM
  • Container security
  • Supply chain security

Application & Code Security

  • Secure SDLC
  • Threat modeling
  • SAST
  • DAST
  • IAST
  • Dependency scanning
  • Semgrep
  • Checkmarx
  • Burp Suite Pro

Offensive Security

  • Cobalt Strike
  • Metasploit
  • BloodHound
  • PowerShell Empire
  • Sliver
  • Havoc
  • SilentTrinity
  • Kali
  • Parrot OS
  • Custom C2

Reverse Engineering

  • Ghidra
  • IDA Pro
  • OllyDbg
  • Exploit development
  • Shellcode authoring
  • AV evasion

Detection & Response

  • Splunk
  • Panther
  • AlienVault (OSSIM/USM)
  • QRadar
  • CrowdStrike Falcon
  • Defender for Endpoint
  • SentinelOne
  • Carbon Black
  • Volatility
  • Wireshark
  • OSQuery
  • Sysmon

AI / LLM Security

  • PyRIT
  • Counterfit
  • Promptfoo
  • Horizon3.ai NodeZero
  • Xbow
  • MITRE ATLAS
  • OWASP Top 10 for LLMs

Programming & Scripting

  • Python
  • Go
  • Rust
  • C
  • C++
  • Bash
  • PowerShell
  • JavaScript
  • Ruby
  • PHP

Frameworks & Standards

  • SOC 2 Type II
  • FedRAMP
  • FISMA
  • NIST CSF
  • NIST SP 800-53
  • NIST SP 800-115
  • ISO 27001/27002
  • PCI DSS 4.0
  • HIPAA
  • HITRUST
  • GDPR
  • COBIT
  • ITIL
  • MITRE ATT&CK
  • MITRE ATLAS
  • OWASP Top 10
  • OWASP Testing Guide
  • PTES
  • CIS Benchmarks
  • SANS Top 20
  • Cyber Kill Chain
07

Get in Touch

Open to vCISO, executive security leadership, and AI security advisory engagements. Reach out for red team operations, security program build-outs, or board-level risk briefings.