Peter Paccione
OSCP | OSCE | CEO | Application Penetration Tester at Secure Consulting Solutions LLC
- Role
- Application Penetration Tester at Secure Consulting Solutions Llc
- Location
- Alexandria, VA, US
- LinkedIn followers
- 500 followers
About Peter Paccione
Offensive Security Specialist | Zero-Day Hunter | Penetration Testing LeaderTurning Vulnerabilities into Fortresses for Over a DecadeAs a battle-tested cybersecurity professional with 10+ years of offensive security leadership, I’ve spent my career dismantling defenses for giants like Google, the Department of Justice, and Alexa Top 500 enterprises—only to rebuild them stronger. My work has uncovered 6 zero-day exploits (including critical CVEs: CVE-20••••91, 20••••07/9508/9509), rooted hardened appliances like FireEye and BlueCoat, and fortified networks against insider/outsider threats for national security agencies.Why Partner With Me? Proven Breaker-and-Builder: Identified critical vulnerabilities (XSS, RCE, SQLi, CSRF) in high-stakes environments, then engineered actionable remediation strategies. Tool Mastery & Innovation: Expert in Burp Suite Pro, Cobalt Strike, Bloodhound, and custom tool creation. Secured APIs (REST/SOAP/XML) across Django.NET, Angular, and more. CVE Credibility: Recognized for weaponizing findings into 4 published CVEs and delivering boardroom-ready reports that bridge technical depth and executive clarity. Full-Spectrum Expertise: From Google Partner Security Assessments to DoD CCRI Phase 3 accreditations, I’ve led red teams, hardened cloud architectures (VMware/ESXi), and architected Splunk/Arcsight SIEM solutions. Risk Slayer: Neutralized threats for the Navy, NIH, and Fortune 500s—averting breaches that could cost millions.Recent Wins Spearheaded penetration tests for 50+ high-value web apps, delivering 95% remediation success rates. Assisted with and found numerous zero day\'s on gov boarder. Assisted in mitigation (CISA) Built Insider Threat programs for classified DOJ networks and hardened $10M+ cloud environments.Let’s Fortify Your Attack SurfaceI’m laser-focused on securing your crown jewels—whether it’s API vulnerabilities, network blind spots, or compliance gaps. Available for 1099/C2C contracts, team engagements, or high-impact project rescues.When adversaries evolve, your defenses need a strategist who’s already three steps ahead.Ready to Test Your Limits? Let’s Talk.
Experience
Application Penetration Tester
Secure Consulting Solutions Llc
Jan 2015 — Present · Arlington, VA, US
Conducted Google Partner Security Assessments, both retesting current partners and perspective Google partners.* Performed Application Penetration Tests on many high-profile web applications. Found numerous critical, high and medium vulnerabilities.* Proficient in understanding application level vulnerabilities like XSS, SQL Injection, CSRF, authentication bypass, cryptographic attacks, authentication flaws etc.* Created professional vulnerability reports to be delivered to Google and sites within the Alexa top 500* Security testing of APIs utilizing protocols such as SOAP, JSON, REST and XML. This includes popular frameworks such as Django, Ruby, Flask,* ASP.NET, jQuery, Angular, Bootstrap and many other custom or commercial frameworks.* Extremely proficient with Burp Suite Pro, proficient in various tools/frameworks, and creating custom tools.* Frequently utilized reporting platforms such as Dradis. Used and modified custom macro’s for report writing* Conducted onsite network penetration tests from an insider/outsider threat perspective.* Utilized tools such as Cobalt Strike, Bloodhound and responder to pull NTLM hashes, crack or “pass the hash” to other specified targets. CS beacons would be deployed once a foothold was obtained.* Recognized by for 6 zero Day findings (two combined into CVE-20••••91), including a severe RCEs, stored XSS and CSRF. CVE’s CVE 20••••07, 20••••08, 20••••09 and CVE-20••••91 were assigned for said findings* Recognized for rooting both FireEye and BlueCoat appliances (referenced in 20••••91)
Education
Frederick Community College
Associates Degree, General Studies
2002 — 2005
University of Maryland Baltimore County
Bachelor of Arts, Political Science
2005 — 2007
Skills
- Firewalls
- Sharepoint
- Vulnerability Assessment
- Access
- Computer Security
- Java
- Security Clearance
- Information Security
- Networking
- Program Management
- System Administration
- Information Assurance
- Vmware Esx
- Network Security
- Computer Hardware
- Security+
- Security
- Servers
- Management
- Dod
- Sql
- Visio
- Html
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.