Maff B.
Director & Penetration Tester @Haven Cybersecurity
Signup · Get unlimited contacts
WORK HISTORY
Director & Penetration Tester @Haven Cybersecurity
Halifax, GB
I\'m a pentester involved in (mainly web application/API) penetration testing and cybersecurity / cloud security best-practice consulting.After web application pentesting (plus occasional network testing), my focus is devloping skills to test the Modbus protocol (both TCP/IP and serial): Modbus is a protocol used in industrial control SCADA/OT systems.I am currently undertaking studies on A.I. project development and deployment and possess some basic A.I. certifications. Separately, as mentioned above, I furthering my Modus testing studies - with an initial focus on remote Modbus TCP/IP testing: future onsite Modbus serial testing being a possibility if the European security situation continues to deteriorate.I also do some AWS account pentesting, whereby compromised \'AWS IAM User\' credentials are simulated with a view to gaining control over AWS cloud resources beyond the level which has been originally designated.
EDUCATION
The Manchester Metropolitan University
Bachelor of Arts (Honours) [BA Hons], Historical Studies
Halifax Catholic High School
A Levels & GCSEs, Various UK curriculum topics
SKILLS
ABOUT MAFF B.
To help recruiters quickly assess fit and save everyone time: Next date available: 16/03/26 NOT INTERESTED in permanent jobs Remote only (~ exceptions for defence work) I don\'t work with any U.S. recruiters or corporations Don\'t mentor or manage Outside IR35 contracts only 8 years\' experience SC-cleared for defence / government work If it’s short-term / overflow work I’m all earsI provide a pentest \"overflow\" service whereby I can help infosec companies by providing them with a temporary additional pentester when their own inhouse testers are fully-deployed. This provides businesses with an easily-scalable additional pentest capacity with no permanent costs or obligations.I\'m an OffSec-/CREST-certified pentester with eight years of pentesting experience and UK MoD SC security clearance, based in Halifax, Yorkshire.* Why use me as an overflow pentester?*• I am \"fire-and-forget\": I will autonomously handle any (already-scoped) pentests from start to finish, with no need for oversight• I write pentest reports in eloquent yet easily-understandable language, with all sections tailored to the relevant customer audience(s)• I get along well with end-clients and communicate with them effectively• My experience means that I\'ve seen most problems already, meaning that I can quickly and autonomously deal with any issuesI\'ve authored and narrated a pentesting course for global training provider Fast Lane, which is probably the world\'s only cybersecurity course narrated in a Halifax accent :)CREST ID: 54••••22SC clearance ID: Available on requestTesting focus: Web applicationsAlso experienced in: Network infrastructure, WiFi, AWS cloud accountEmerging skills: LLM, IoT, roboticsSome pentest triumphs across my career are:• Exfiltrating data from an internal server, evading egress firewall rules by smuggling data in DNS lookup queries to an internet-based self-authoritative DNS server under my own control• Cracking the JWT authentication token on a website, allowing me to forge my own authentication tokens as any user of the application• Reversing “send” transactions on a website so that funds flowed TO me rather than AWAY, allowing me to “steal” funds off other users (within a pentest \"staging\" framework)• Discovering web app database login info in public-facing code• Accessing an admin-level user on a corporate network via the SMB Relay Attack• Discovering a public AWS S3 Bucket containing sensitive HR data• Ensuring Oxford-based scientific research units were secure against data exfiltration
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.