Zachary S Stashis
Organizer & Co-Founder at Hack Space Con- Claim this Profile
Click to upgrade to our gold package
for the full feature experience.
-
English Native or bilingual proficiency
-
Sarcasm Full professional proficiency
Topline Score
Bio
Credentials
-
GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)
GIAC CertificationsAug, 2019- Nov, 2024 -
GIAC Web Application Penetration Tester (GWAPT)
GIAC CertificationsMay, 2019- Nov, 2024 -
GIAC Certified Incident Handler (GCIH)
GIAC CertificationsDec, 2018- Nov, 2024 -
OSCP - Offensive Security Certified Professional
Offensive SecurityFeb, 2018- Nov, 2024 -
GIAC Security Leadership (GSLC)
GIAC CertificationsSep, 2017- Nov, 2024 -
GIAC Advisory Board
GIAC CertificationsJun, 2017- Nov, 2024 -
GIAC Penetration Tester (GPEN)
GIAC CertificationsJun, 2017- Nov, 2024 -
CompTIA A+ ce
CompTIAMay, 2016- Nov, 2024
Experience
-
Hack Space Con
-
United States
-
Technology, Information and Internet
-
1 - 100 Employee
-
Organizer & Co-Founder
-
Nov 2022 - Present
-
-
-
Hack Red Con
-
United States
-
Computer and Network Security
-
1 - 100 Employee
-
Co-Founder
-
Jun 2021 - Present
-
-
-
Express Scripts
-
United States
-
Hospitals and Health Care
-
700 & Above Employee
-
Senior Manager, Information Protection
-
Dec 2021 - Present
In December 2021 I was promoted to Sr. Manager (Information Protection Senior Manager)
-
-
Penetration Test Team Lead, Information Protection Senior Advisor
-
Apr 2021 - Dec 2021
In April 2021 I was promoted to Team Lead (Information Protection Senior Advisor)
-
-
Senior Penetration Tester, Information Protection Advisor
-
Mar 2020 - Apr 2021
In March 2020, I converted from Contractor to FTE with Cigna/Express-Scripts. Specializing in Web Application/Mobile Application/Network Penetration Testing, Vulnerability Assessments, and Red Team Campaigns. Adhering to strict HIPAA, FISMA, PCI and SOX policies/regulations securing our network and applications on a daily basis. Creating documentation on advanced attack scenarios and tool usage for our team.
-
-
-
Red Seer Security
-
United States
-
Computer and Network Security
-
1 - 100 Employee
-
CEO, Founder, Educator, Speaker
-
Jul 2018 - Present
RED SEER is a Cybersecurity advisory and consulting firm that specializes in Offensive Security, Red Teaming, Penetration Testing and Social Engineering of Digital Assets, Web Applications, Mobile Applications, Cloud and Network Infrastructure, Application Protocol Interfaces (API's), Wireless and Rogue Devices and Managed Services. Our team elite experts specialize in Financial, Insurance, Commodities, Healthcare, Technology and Enterprise Markets. RED SEER is a Cybersecurity advisory and consulting firm that specializes in Offensive Security, Red Teaming, Penetration Testing and Social Engineering of Digital Assets, Web Applications, Mobile Applications, Cloud and Network Infrastructure, Application Protocol Interfaces (API's), Wireless and Rogue Devices and Managed Services. Our team elite experts specialize in Financial, Insurance, Commodities, Healthcare, Technology and Enterprise Markets.
-
-
-
Solution Consultants, Inc.
-
Remote
-
Senior Web Application Penetration Tester (Contractor for Express-Scripts/Cigna healthcare)
-
Oct 2019 - Mar 2020
Specializing in Web Application/Mobile Application/Network Penetration Testing, Vulnerability Assessments, and Red Team Campaigns. Adhering to strict HIPAA, FISMA, PCI and SOX policies/regulations securing our network and applications on a daily basis. Creating documentation on advanced attack scenarios and tool usage for our team. Specializing in Web Application/Mobile Application/Network Penetration Testing, Vulnerability Assessments, and Red Team Campaigns. Adhering to strict HIPAA, FISMA, PCI and SOX policies/regulations securing our network and applications on a daily basis. Creating documentation on advanced attack scenarios and tool usage for our team.
-
-
-
Macy's Systems and Technology
-
Greater Atlanta Area
-
Senior Penetration Tester, Senior Security Engineer
-
Apr 2018 - Oct 2019
Senior Penetration Tester for the Vulnerability Management team. Perform network, infrastructure, web application and mobile penetration tests. Create detailed penetration test reports. Monitor and track progress of found vulnerabilities. Explain and demonstrate vulnerabilities to application/system owners, while providing recommendations for remediation. Worked hand in hand with the application security (ApSec) team and vulnerability management teams. Daily research and test new… Show more Senior Penetration Tester for the Vulnerability Management team. Perform network, infrastructure, web application and mobile penetration tests. Create detailed penetration test reports. Monitor and track progress of found vulnerabilities. Explain and demonstrate vulnerabilities to application/system owners, while providing recommendations for remediation. Worked hand in hand with the application security (ApSec) team and vulnerability management teams. Daily research and test new vulnerabilities. Show less Senior Penetration Tester for the Vulnerability Management team. Perform network, infrastructure, web application and mobile penetration tests. Create detailed penetration test reports. Monitor and track progress of found vulnerabilities. Explain and demonstrate vulnerabilities to application/system owners, while providing recommendations for remediation. Worked hand in hand with the application security (ApSec) team and vulnerability management teams. Daily research and test new… Show more Senior Penetration Tester for the Vulnerability Management team. Perform network, infrastructure, web application and mobile penetration tests. Create detailed penetration test reports. Monitor and track progress of found vulnerabilities. Explain and demonstrate vulnerabilities to application/system owners, while providing recommendations for remediation. Worked hand in hand with the application security (ApSec) team and vulnerability management teams. Daily research and test new vulnerabilities. Show less
-
-
-
ACI Worldwide
-
United States
-
Software Development
-
700 & Above Employee
-
Senior Security Analyst/Penetration Tester
-
Dec 2017 - Apr 2018
Red Team activities including web app, internal, and external penetration testing, open source intelligence gathering, and vulnerability scanning. Worked with environment project managers to plan, perform, and report penetration test activities; as well as coordinated with red team members to facilitate activities. Configured and validated secured environments. Monitored, evaluated and maintained secured networks and environments through the use of security tools, processes, and procedures… Show more Red Team activities including web app, internal, and external penetration testing, open source intelligence gathering, and vulnerability scanning. Worked with environment project managers to plan, perform, and report penetration test activities; as well as coordinated with red team members to facilitate activities. Configured and validated secured environments. Monitored, evaluated and maintained secured networks and environments through the use of security tools, processes, and procedures. Monthly IPT and EPT tests to meet PCI compliance. Led Remediation efforts. Vulnerability and Security Research. Created training penetration testing training program for mentoring. Show less Red Team activities including web app, internal, and external penetration testing, open source intelligence gathering, and vulnerability scanning. Worked with environment project managers to plan, perform, and report penetration test activities; as well as coordinated with red team members to facilitate activities. Configured and validated secured environments. Monitored, evaluated and maintained secured networks and environments through the use of security tools, processes, and procedures… Show more Red Team activities including web app, internal, and external penetration testing, open source intelligence gathering, and vulnerability scanning. Worked with environment project managers to plan, perform, and report penetration test activities; as well as coordinated with red team members to facilitate activities. Configured and validated secured environments. Monitored, evaluated and maintained secured networks and environments through the use of security tools, processes, and procedures. Monthly IPT and EPT tests to meet PCI compliance. Led Remediation efforts. Vulnerability and Security Research. Created training penetration testing training program for mentoring. Show less
-
-
-
Gladius
-
Remote
-
Penetration Tester
-
Jan 2017 - Feb 2018
Network Penetration Testing, Vulnerability Analysis, Web-App Penetration Testing Network Penetration Testing, Vulnerability Analysis, Web-App Penetration Testing
-
-
-
Vonage
-
United States
-
IT Services and IT Consulting
-
700 & Above Employee
-
Business Technical Support
-
Sep 2016 - Jan 2017
Primary responsibilities included configuring/hardening networks, fielding inbound calls and resolving technical issues concerning RTP, VoIP and SIP Traffic. As well as commonly assisted with team projects and questions. Handled customer calls varying from phone setup to in-depth Wireshark network analysis including Modem, Router, and Firewall (Dell Sonicwall, Fortinet Fortigate, AirOS, DD-WRT, Mikrotik, Tomato, Ubiquiti, and some Cisco models) setup and configuration. • Provided… Show more Primary responsibilities included configuring/hardening networks, fielding inbound calls and resolving technical issues concerning RTP, VoIP and SIP Traffic. As well as commonly assisted with team projects and questions. Handled customer calls varying from phone setup to in-depth Wireshark network analysis including Modem, Router, and Firewall (Dell Sonicwall, Fortinet Fortigate, AirOS, DD-WRT, Mikrotik, Tomato, Ubiquiti, and some Cisco models) setup and configuration. • Provided customer-focused support using clear and descriptive methods • Investigated alerts and took appropriate measures to secure and prevent fraudulent activity on customer accounts. • Managed and completed projects in a timely manner • Determined source of problems (hardware, software, user access, etc.) • Documented resolutions for future reference both internally and externally • Tracked case tickets within Sales Force Customer Relations Management (CRM) System to Document resolutions for future reference both internally and externally • Used JIRA to Collaborate with internal departments to document, replicate, troubleshoot and resolve systemic bugs and third-party errors within a test environment. Show less Primary responsibilities included configuring/hardening networks, fielding inbound calls and resolving technical issues concerning RTP, VoIP and SIP Traffic. As well as commonly assisted with team projects and questions. Handled customer calls varying from phone setup to in-depth Wireshark network analysis including Modem, Router, and Firewall (Dell Sonicwall, Fortinet Fortigate, AirOS, DD-WRT, Mikrotik, Tomato, Ubiquiti, and some Cisco models) setup and configuration. • Provided… Show more Primary responsibilities included configuring/hardening networks, fielding inbound calls and resolving technical issues concerning RTP, VoIP and SIP Traffic. As well as commonly assisted with team projects and questions. Handled customer calls varying from phone setup to in-depth Wireshark network analysis including Modem, Router, and Firewall (Dell Sonicwall, Fortinet Fortigate, AirOS, DD-WRT, Mikrotik, Tomato, Ubiquiti, and some Cisco models) setup and configuration. • Provided customer-focused support using clear and descriptive methods • Investigated alerts and took appropriate measures to secure and prevent fraudulent activity on customer accounts. • Managed and completed projects in a timely manner • Determined source of problems (hardware, software, user access, etc.) • Documented resolutions for future reference both internally and externally • Tracked case tickets within Sales Force Customer Relations Management (CRM) System to Document resolutions for future reference both internally and externally • Used JIRA to Collaborate with internal departments to document, replicate, troubleshoot and resolve systemic bugs and third-party errors within a test environment. Show less
-
-
-
Camber Corporation - Technical Solutions Group Huntington Ingalls Industries
-
United States
-
Defense and Space Manufacturing
-
500 - 600 Employee
-
Technical Support and Administrative Specialist
-
Jan 2014 - Jul 2016
Assisted Veterans Association (VA) Training Managers and Training Chiefs with technical issues. VA Learning Management System (LMS) (also known as SuccessFactors LMS by the private sector) and VA SharePoint administrator and national help desk technician. Daily execution of Software as a Service (SaaS). Created and assigned national training evaluations and enforced VA employee compliance. Created SOPs and Job Aids (utilizing Adobe Captivate) in response to technical support e-mails. VA Talent… Show more Assisted Veterans Association (VA) Training Managers and Training Chiefs with technical issues. VA Learning Management System (LMS) (also known as SuccessFactors LMS by the private sector) and VA SharePoint administrator and national help desk technician. Daily execution of Software as a Service (SaaS). Created and assigned national training evaluations and enforced VA employee compliance. Created SOPs and Job Aids (utilizing Adobe Captivate) in response to technical support e-mails. VA Talent Management System (TMS) and SuccessFactors LMS subject matter expert (SME) and administrator. Applied time management and critical thinking skills to identify daily arduous tasks, created advanced Excel macros to save the company both time and money. Drafted clear, concise e-mails explaining complex technical solutions to Veterans Benefits Association (VBA) employees. Technical support up to and including Tier 3 support. • Created advanced Excel macros for the national compliance of the “Health Insurance Portability and Accountability Act” (HIPAA) and the “Federal Information Security Management Act” (FISMA); that reduced the daily manual work to 2 hours daily (down 66.67%) saving my company 1,360 working hours in one year • Maintained national VA (over 28,000 employees) compliance above 99% for both HIPAA and FISMA • Utilized advanced Excel formulas and features (V-lookups, Pivot tables, conditional formatting) streamlining daily tasks and reports to increase productivity of entire team Show less Assisted Veterans Association (VA) Training Managers and Training Chiefs with technical issues. VA Learning Management System (LMS) (also known as SuccessFactors LMS by the private sector) and VA SharePoint administrator and national help desk technician. Daily execution of Software as a Service (SaaS). Created and assigned national training evaluations and enforced VA employee compliance. Created SOPs and Job Aids (utilizing Adobe Captivate) in response to technical support e-mails. VA Talent… Show more Assisted Veterans Association (VA) Training Managers and Training Chiefs with technical issues. VA Learning Management System (LMS) (also known as SuccessFactors LMS by the private sector) and VA SharePoint administrator and national help desk technician. Daily execution of Software as a Service (SaaS). Created and assigned national training evaluations and enforced VA employee compliance. Created SOPs and Job Aids (utilizing Adobe Captivate) in response to technical support e-mails. VA Talent Management System (TMS) and SuccessFactors LMS subject matter expert (SME) and administrator. Applied time management and critical thinking skills to identify daily arduous tasks, created advanced Excel macros to save the company both time and money. Drafted clear, concise e-mails explaining complex technical solutions to Veterans Benefits Association (VBA) employees. Technical support up to and including Tier 3 support. • Created advanced Excel macros for the national compliance of the “Health Insurance Portability and Accountability Act” (HIPAA) and the “Federal Information Security Management Act” (FISMA); that reduced the daily manual work to 2 hours daily (down 66.67%) saving my company 1,360 working hours in one year • Maintained national VA (over 28,000 employees) compliance above 99% for both HIPAA and FISMA • Utilized advanced Excel formulas and features (V-lookups, Pivot tables, conditional formatting) streamlining daily tasks and reports to increase productivity of entire team Show less
-
-
-
Genius Computer Repair
-
Gainesville, Orlando, and Remote
-
Owner, Lead Technician, Information Security Specialist
-
May 2008 - Jul 2016
• Tested small/medium-sized business websites for OWASP top 10. • Created simple automation scripts in Python, Visual Basic, PowerShell, Batch (Windows command line) and Bash (Linux terminal) • Installed, configured, secured and updated operating systems. • Network installation, configuration, and security (hardening). • Installing VPN Host and Client solutions. • Performed: Network Vulnerability Assessments, Wifi Security Audits, VoIP security assessments… Show more • Tested small/medium-sized business websites for OWASP top 10. • Created simple automation scripts in Python, Visual Basic, PowerShell, Batch (Windows command line) and Bash (Linux terminal) • Installed, configured, secured and updated operating systems. • Network installation, configuration, and security (hardening). • Installing VPN Host and Client solutions. • Performed: Network Vulnerability Assessments, Wifi Security Audits, VoIP security assessments, • Installed/updated system protection and configured firewalls. • Removed viruses, malware, and ransomware. • Educated customers and their employees about continued safe use regarding information security. • Expert in installing, maintaining and supporting computer equipment. • Built custom computers. • Lead team of 7 technicians. Show less • Tested small/medium-sized business websites for OWASP top 10. • Created simple automation scripts in Python, Visual Basic, PowerShell, Batch (Windows command line) and Bash (Linux terminal) • Installed, configured, secured and updated operating systems. • Network installation, configuration, and security (hardening). • Installing VPN Host and Client solutions. • Performed: Network Vulnerability Assessments, Wifi Security Audits, VoIP security assessments… Show more • Tested small/medium-sized business websites for OWASP top 10. • Created simple automation scripts in Python, Visual Basic, PowerShell, Batch (Windows command line) and Bash (Linux terminal) • Installed, configured, secured and updated operating systems. • Network installation, configuration, and security (hardening). • Installing VPN Host and Client solutions. • Performed: Network Vulnerability Assessments, Wifi Security Audits, VoIP security assessments, • Installed/updated system protection and configured firewalls. • Removed viruses, malware, and ransomware. • Educated customers and their employees about continued safe use regarding information security. • Expert in installing, maintaining and supporting computer equipment. • Built custom computers. • Lead team of 7 technicians. Show less
-
-
Education
-
Southern New Hampshire University
Bachelor of Science (B.S.), Information Technology -
University of Florida
NA, Marketing/Marketing Management, General -
Broward College
Associate of Arts (AA), Business Administration and Management, General -
SANS Technology Institute
Penetration Testing