Adam Raaymakers
Senior Cybersecurity Engineer & Penetration Tester
LinkedIn · Email · Resume (PDF) · DOD TS/SCI Cleared
Offensive security engineer with 10+ years in IT and 6+ in penetration testing, specializing in web application, network, and embedded/OT assessments for DoD and Fortune 100 clients. OSCP+ certified. Led red/purple team engagements simulating APT TTPs against classified developmental weapon systems, cut system vulnerabilities by 19% on a $40M risk-reduction program, and delivered 150+ vulnerabilities across FedRAMP and Fortune 100 web app tests. DoD TS/SCI (CM).
Experience
Senior Security Consultant
- Lead comprehensive penetration testing engagements across client applications, networks, and systems using manual exploitation and automated tooling to identify exploitable risk
- Advise Cybersecurity and Engineering teams on security posture improvements, supporting Incident Response through active participation in purple team exercises
- Architect a continuous security testing platform to complement existing vulnerability scanning, extending detection coverage beyond point-in-time assessments
Senior Principal Cyber Systems Engineer
Leading advanced penetration testing and cyber survivability assessments against developmental classified weapon systems, operating where most offensive security engineers never get clearance to go.
- Led advanced penetration testing across developmental system (DT) environments, simulating APT-level TTPs to identify critical vulnerabilities in classified weapon systems
- Led a 7-member cross-functional team on a $40M cybersecurity risk-reduction initiative, achieving a 19% decrease in weapon system vulnerabilities
- Co-authored multiple system-level cybersecurity documents establishing weapon system-wide cyber test procedure guidance and enhancing overall weapon system security
- Designed and executed advanced cyber testing methodologies for complex developmental systems
- Built automated cybersecurity controls and test procedures, improving security validation efficiency across multiple platforms
- Orchestrated the development of systems of interest through the entire life cycle, from requirements determination through operations
- Created and taught a hands-on 'Pentesting Foundations' boot camp (threat modeling, OWASP Top 10, recon, exploitation, reporting); mentored a cohort of 8 junior analysts
Information System Security Engineer
Not every role is a red team engagement. This one was about understanding how complex systems get built, secured, and delivered across multi-stakeholder defense environments.
- Led IT modernization by migrating legacy systems into secure cloud environments while maintaining compliance and boosting performance and security posture
- Implemented DevSecOps practices across the development lifecycle, reducing production vulnerabilities in final testing
- Engineered cloud-based RMF implementations and ATO packages for federal client migration
- Hardened agile software environments using automated compliance testing and patching
- Partnered with DevSecOps teams to strengthen CI/CD pipeline security controls
- Managed day-to-day operations of security-related programs; assessed threat landscapes and solution costs to prioritize risk reduction
Senior Security Consultant
Offensive security and compliance consulting for federal clients navigating high-risk legacy infrastructure overhauls. The compliance work paid the bills. The pentesting was the fun part.
- Provided cybersecurity expertise during a complete legacy system upgrade to a major federal client, achieving 100% successful compliance assessments during transition
- Conducted FedRAMP penetration testing for small businesses, identifying 150+ vulnerabilities with actionable remediation roadmaps that accelerated compliance and strengthened client security posture
- Provided SME insight on cybersecurity tasks to large federal accounts
- Delivered executive-level risk reports and technical security control mappings
- Maintained a Vulnerability Management Program using Nessus Security Center
- Assisted the CISO with implementing and responding to policy updates and mandates
Web Application Penetration Tester
NetSPI is one of the most respected names in offensive security consulting. Four months. 25+ engagements. Fortune 100 clients. Not a lot of people can say that.
- Led 25+ web application penetration tests for Fortune 100 clients, identifying critical flaws aligned with OWASP Top 10
- Delivered comprehensive technical reports translating security findings into business risk reduction recommendations
- Used Burp Suite, Metasploit, Kali Linux (automated + manual techniques)
- Assisted customers in understanding risk and threat levels associated with vulnerabilities
Cyber Security Engineer
Where the offensive security foundation got built. First real exposure to structured adversary emulation, ATT&CK mapping, and red/purple team operations against DoD environments.
- Developed attack path vectors using MITRE Caldera and mapped threat scenarios via MITRE ATT&CK for red/purple team exercises
- Collaborated with cloud architects to integrate multi-cloud environments into a centralized SIEM
- Led active cyber defense and purple team operations using the MITRE ATT&CK framework
- Developed a multi-platform phishing campaign covering 6 email domains; created remedial training for affected personnel
- Co-authored Incident Response Playbooks and Blue Team guides for new hires
- Created and maintained ELK dashboards for security monitoring
Cybersecurity Engineer
Weapon systems cybersecurity before it was cool. Assessing embedded aviation platforms for exploitable vulnerabilities requires a different mindset than enterprise pentesting, and this is where that muscle got developed.
- Conducted cybersecurity assessments of aircraft weapon systems, developing protocols that identified 11+ critical vulnerabilities
- Revamped the aviation weapon system Authority to Operate (ATO) package by incorporating advanced threat modeling techniques
- Established cybersecurity baseline standards for embedded aviation systems across multiple aircraft platforms
- Assessed complete aircraft weapon systems to ensure proper cybersecurity posture
- Formulated testing plans and concepts in coordination with software developers for timely upgrades
- Managed communications with 8 Air Force agencies/mission defense teams; tracked KOIs on future weapon system designs
- Developed, maintained, and semi-annually updated weapon system cyber awareness training for aircraft maintenance personnel
Cyber Security Analyst (SOC)
The blue team chapter. Understanding how defenders think, what they see, and where their blind spots are makes for a better attacker.
- Managed security event correlation across 500+ systems using Splunk and ELK Stacks for comprehensive threat detection
- Conducted network traffic analysis and forensic investigations, mitigating incidents and correlating them to the MITRE ATT&CK framework
- Produced security trend analysis reports for senior management, contributing to strategic security investment decisions
- Correlated all reported events from various systems and network areas where potential security incidents were identified
- Produced and maintained SIEM dashboards based on Indicators of Compromise (IOC)
- Analyzed cybersecurity of highly classified communications networks
- Triaged multiple security alerts daily, identifying malicious actors on customer networks
Information Assurance Specialist II
Short engagement due to contract loss. Executed information assurance sustainment activities across hardware/software change management and account lifecycle management.
- Executed information assurance sustainment activities including hardware/software change management and account lifecycle management per NIST SP 800-53, DISA STIGs, and ISO 27001
- Identified automated information system (AIS) vulnerabilities and ensured nodes were operated, maintained, and disposed of per security policy
- Maintained file servers, firewalls, network access, and security monitoring systems
- Supported live flight operational tests in accordance with Security Test & Evaluation (ST&E)
- Supervised work of other IS engineers performing daily information security tasks
F-35 Field Service Engineer
The beginning of understanding how classified embedded systems are built, administered, and secured. Working inside F-35 training environments gave early exposure to the infrastructure that later became a target.
- Managed Active Directory, DNS, DHCP, and domain controllers for F-35 training systems across CONUS/OCONUS, maintaining 24/7 operational capability
- Implemented security controls following NIST 800-53 and STIG guidelines for classified training environments
- Administered 250+ Windows devices for F-35 training systems
- Managed installation, sustainment, and scheduled maintenance of F-35 training devices in CONUS and OCONUS
- Executed account management policy via Active Directory; created, modified, and deleted user accounts and security groups
- Maintained system availability and uptime through internal and external backups and virtual image restoration
- Installed, updated, maintained, and troubleshot switch firewalls, RAIDs, and LANs
Aircraft Mechanic
20 years. Multiple airframes. The wrench-turning built the discipline. The instructor role pointed it at a keyboard.
- Led aircraft launch/recovery operations and managed maintenance supporting 8,000+ annual flying hours at 82% mission-ready
- Performed system administration and user support for aircraft technical order systems, ensuring secure access, data integrity, and operational readiness
- Served across F-15E, F-22, A-10, and C-146 platforms
- Led 240+ personnel while coordinating 7 different Air Force Specialty Codes
- Certified crash/damage/disabled aircraft recovery team lead; led crash site recovery engagements
- Managed Government Travel Card program for 140+ members (0 discrepancies across multiple Wing-level audits)
- Maintained 400+ pieces of specialized equipment and 1,800 Technical Order files
Certifications
Offensive Security
TCM Security
Other
- Certified Legacy Off-Road Recovery Specialist
CompTIA
- CompTIA SecurityX (CASP+)
- CompTIA PenTest+
- CompTIA Linux+
- CompTIA Security+
- CompTIA Network+
- CompTIA A+
Education
Western Governors University
MBA, Information Technology Management (2026)
University of Maryland
B.S. Computer Networks & Cyber Security (2020)
Community College of the Air Force
A.A. Applied Science, Aviation Maintenance Technology (2012)
Home Lab
Offensive Security Lab
- Dedicated, internet-isolated offensive-lab VLAN segmented for adversarial testing
- GOAD (Game of Active Directory) for hands-on AD attack/defense: LLMNR poisoning, SMB relay, Kerberoasting, ADCS exploitation, Pass-the-Hash
- Vulnerable targets for web & network testing: DVWA, Juice Shop, Metasploitable 3
- MITRE Caldera and open-source C2 frameworks for adversary emulation; recent CVE exploitation and red team attack pathways
- SysReptor — self-hosted penetration-test report writing for certification and lab reports
Local LLM & AI Red Teaming
- Local LLM inference via llama.cpp, GPU passthrough to a Proxmox VM, isolated model-serving containers
- Primary model + secondary coder/embedder models on a second GPU, wired into a local coding agent and chat UI
- Hands-on AI/ML security: building an AI-powered adversarial tester, log-triage agent, and autonomous red-team/C2 operator (in build, tied to the White Knight Labs course)
Detection & Blue Team
- Security Onion and Wazuh SIEM for detection, hunting, and alert tuning
- TheHive + Cortex for incident-response case management and observability
- Velociraptor for host forensics and threat hunting
- ELK/Kibana for SIEM log-analysis practice
Professional Training
White Knight Labs: AI-Powered Red Teaming & C2 Operator Creation (In-Work)
Red Team Leaders: Intro to Offensive Security with Artificial Intelligence (2025)
Simply Cyber Academy: Introduction to AWS Penetration Testing (2025)
PortSwigger Web Security Academy: Top 5K globally
Hack The Box: Active Participant