About

Security across code, cloud, and investigations.

I’m Brandon Bennett — a penetration tester and cybersecurity analyst working at the intersection of offensive security, cloud and Microsoft 365 security, OSINT and financial-crime investigations, and AI-driven security operations. I find real-world vulnerabilities, harden the environments around them, and trace the connections others miss.

What I do

Five practices, one goal: reduce real risk.

01 Offensive Security

Penetration testing across REST and GraphQL, mapped to the OWASP Top 10 and reported with prioritized remediation.

02 Cloud & Microsoft 365

Hardening identity, endpoints, and compliance across Entra ID, Intune, Exchange, Defender, and Purview.

03 GRC & Automation

Control design and audit readiness, automated with Python, PowerShell, and Golang.

04 Prompt Engineering

Applying LLMs to accelerate security analysis, triage, and tooling, and evaluating AI models for development.

05 OSINT & Investigations

Open-source intelligence, cybercrime investigations, and AML/CFT analysis of ownership and sanctions risk.

Experience

Where I’ve done the work.

Jul 2023 – Jul 2024
Contract · Remote

Cybersecurity Analyst · Penetration Tester · Microsoft 365 Administrator

Security Overview
  • Ran contract and quarterly penetration tests against REST and GraphQL applications; identified and assessed 30+ OWASP Top 10 vulnerabilities and delivered client reports with risk ratings and remediation.
  • Administered Microsoft 365 and Apple Business Essentials — Entra ID, Intune, Exchange, SharePoint, OneDrive, Defender, Teams, and Purview.
  • Hardened IAM with SAML/SSO, enforced MFA and geo-restrictions, and encrypted endpoints with BitLocker and FileVault.
  • Built compliance controls aligned with NIST, SOC 2, PCI-DSS, GDPR, ISO 27001, and CIS, supporting successful client audits.
May 2023 – Sep 2024
Internship · Remote

Prompt Engineer

Proof of Reception
  • Applied prompt engineering across AI models to improve application development, code quality, and vulnerability management within the SDLC.
  • Analyzed code for vulnerabilities and optimized functions using Python, Golang, and React Native.
  • Worked hands-on with GPT-4, DALL·E 2, Copilot, Llama, and Stable Diffusion.
Education

Where I trained.

Oct 2022 – Jun 2023
4.0 GPA · Director’s List

Cybersecurity

Woz U
  • Completed a comprehensive program in penetration testing, cloud security, network security, vulnerability assessment, and secure systems administration.
  • Built a pfSense home lab with Snort IDS/IPS; created and competed in CTF events and hosted workshops for classmates.
Skills & tools

The stack I work in.

Offensive Security

Burp SuiteNmapMetasploitGraphQL VoyagerAltairInQLWiresharkOWASP Top 10

Cloud & Microsoft 365

Entra IDIntuneExchangeDefenderPurviewSharePointAzureMicrosoft SentinelApple Business Essentials

GRC & Frameworks

NISTCISISO 27001SOC 2PCI-DSSGDPR

Development & AI

PythonPowerShellGolangReact NativePrompt Engineering

OSINT & Investigations

MaltegoLink AnalysisAML/CFTSanctions ScreeningOpSec
Certifications

40+ certifications. Selected highlights.

See projects →
Practical Bug Bounty — TCM Security Maltego — Cybercrime Investigations Basel Institute — Combating Financial Terrorism Basel Institute — Open-Source Intelligence OpSec — Just Hacking Training IBM Cybersecurity Analyst — Coursera Certified in Cybersecurity — ISC2 Google IT Support — Coursera

Have a target, an environment, or an investigation?

Get in touch →