End of an Era!

End of an Era!

After 10 years, I have resigned from a “large financial” today. I will announce my next adventure on June 1. For now, I want to look back on the past 10 years, at least what I can publish, because large financials are like Fight Club (the first rule of Fight Club: you do not talk about Fight Club).

In June 2010 I started as an infrastructure vulnerability assessment analyst in a team of 6 ethical hackers. I began learning about offensive security, how to bring value, and how to portray risk in a manner that is actionable for reduction. I recently took SANS SEC504 where I learned about hacker techniques and exploits.

Exploit all the things! We matured from vulnerability assessment to penetration testing and exploiting new products before they were purchased from vendors and deployed into production. This was amazing leverage as products with high risk vulnerabilities would not be allowed to go into production. We found over 30 0days that received CVEs with high or critical risk CVSS. This was fulfilling because the industry would get patches for vulnerabilities we found. The downside is that no one in the community will ever know these were found by me or my team. It was tough at first to overcome this because street cred is a thing in infosec.

In 2011, The Hackers Choice (THC) created an SSL renegotiation Denial of Service tool. I got my hands on a leaked version and tested it out. No one was talking about it, yet organizations were getting DDOSed on the daily. So, I blogged about it to raise awareness… this is when I learned the rules of fight club.

That near-termination experience led me to erase all traces and associations of my employer and me from the Internet. Yes, you can find what “large financial” this is but it will take you longer than you care to spend on it. I did this to be able to speak and teach without too much red tape. From that point, I had to decide between growing at the organization or growing in the community. I chose the job but was not happy it couldn’t be both. It brings me a lot of joy giving back to the community!

I learned and experienced just about anything you can imagine in corporate America. I also made relationships that will last a lifetime and for this, I am eternally grateful.

Here’s some highlights I can share:

  • Moved from an officer to Director in 10 years
  • Began growing by becoming team lead, then manager of infrastructure testing
  • Created the Red Team in 2015, one of the first in the financial services industry and one of the top accomplishments to this day
  • Led application penetration testing team
  • Grew team to 140 ethical hackers globally
  • Created the coordinated vulnerability disclosure program
  • Founding member of FS-ISAC and FIRST Red Team Special Interest Groups
  • SIFMA/GFMA Penetration Testing Working Group and release of threat-led penetration testing framework
  • CVSS Voting Member releasing CVSSv3.0 and CVSSv3.1
  • Founding Member of MITRE Engenuity Center for Threat-Informed Defense

Here’s what I’ll be up to in the next month, you should join me:

I look back at the past 10 years and they are all excellent memories. Learned a lot, grew a lot, and now I am ready for the next big thing. I appreciate all your support and hope I can continue to bring value to you and your organizations. 

Enzo Alvarez

Security Professional

4 年

Lol @Robert's screen cap. Best of luck to you brother. I know you gonna shine wherever you go.

Maria McFarlane

Technology & Telecommunications Professional

4 年

Congrats Jorge!!

回复
Juan Carlos Benavente

Head of Fraud Prevention

4 年

Congrats Mr Orchilles, best of luck buddy

要查看或添加评论,请登录

Jorge Orchilles的更多文章

  • C2 Matrix

    C2 Matrix

    The goal of the C2 Matrix is to document, compare, and contrast C2 frameworks to facilitate the determination of the…

    1 条评论
  • Reading for?Hackers

    Reading for?Hackers

    I was recently asked to recommend books for students and people looking to get into information security. Reading is…

    8 条评论

社区洞察

其他会员也浏览了