mlaoudis@arizona:~$ man mlaoudis
Michael Laoudis
penetration tester · bug bounty hunter · web security researcher
mlaoudis --pentest --bugbounty --websec
--location=Peoria,AZ --contact=michaellaoudis@gmail.com
Results-driven cybersecurity professional specializing in vulnerability assessments, penetration testing, and enterprise IT infrastructure security. Experienced in assessing web applications, APIs, databases, and Windows/Linux environments, with prior SOC experience triaging and remediating incidents in a 24/7 operations environment.
Delivers penetration testing and risk assessments primarily for government-sector clients as a government contractor holding a Public Trust position, with a focus on web application security testing and remediation.
- Delivered client-facing engagements, including kick-off presentations to define testing scope and post-engagement debriefs to clearly communicate findings, risk impact, and remediation recommendations
- Utilized Python and PowerShell scripting to automate workflows, including transforming raw JSON output from Trivy vulnerability scans into structured Excel reports for improved analysis
- Conducted engagements for government-sector clients, assessing web applications, internal network environments, databases, and APIs, applying frameworks such as OWASP Top 10, NIST SP 800-53, and CIS Benchmarks
- Regularly perform manual source code reviews across engagements, identifying vulnerabilities missed by automated scanning (e.g. blind SQL injection in unsanitized query parameters) and delivering client-facing writeups with proof-of-concept evidence and remediation guidance
- Mentored and onboarded junior penetration testers by providing guidance on internal tooling, testing methodologies, and stakeholder communication to support effective delivery
- Led mentorship and training of IT Operations staff in security detection, investigation, and escalation processes
- Investigated over 40 user-reported phishing emails by identifying malicious indicators such as spoofed headers, relayed IP addresses, and social engineering techniques
- Reduced alert fatigue by identifying and communicating hundreds of false-positive detections to clients for tuning, ensuring only genuine suspicious activity triggered investigation in a 24x7 SOC environment
- Presented weekly security metrics to client stakeholders, including detection volume across Splunk, CrowdStrike, and Vectra, true/false positive rates, and status of open escalations, translating technical findings into actionable insights for non-technical audiences
- Provided Tier 1 and 2 IT support to clients over phone and email by remotely troubleshooting issues related to computer/printer hardware and software, Windows administration, TCP/IP networking, and Active Directory
- Identified and reported 3 high-impact and 2 medium-impact vulnerabilities in live websites, including a stored cross-site scripting vulnerability leveraged for full account takeover on a production web application
- Performed offensive security testing of web applications for vulnerabilities on the OWASP Top 10 by utilizing tools such as Kali Linux, Burp Suite Pro, OWASP Amass, Nmap, Metasploit Framework, and Python/Bash scripting