Security across code, cloud, and investigations.
I’m Brandon Bennett — a penetration tester and cybersecurity analyst working at the intersection of offensive security, cloud and Microsoft 365 security, OSINT and financial-crime investigations, and AI-driven security operations. I find real-world vulnerabilities, harden the environments around them, and trace the connections others miss.
Five practices, one goal: reduce real risk.
01 Offensive Security
Penetration testing across REST and GraphQL, mapped to the OWASP Top 10 and reported with prioritized remediation.
02 Cloud & Microsoft 365
Hardening identity, endpoints, and compliance across Entra ID, Intune, Exchange, Defender, and Purview.
03 GRC & Automation
Control design and audit readiness, automated with Python, PowerShell, and Golang.
04 Prompt Engineering
Applying LLMs to accelerate security analysis, triage, and tooling, and evaluating AI models for development.
05 OSINT & Investigations
Open-source intelligence, cybercrime investigations, and AML/CFT analysis of ownership and sanctions risk.
Where I’ve done the work.
Contract · Remote
Cybersecurity Analyst · Penetration Tester · Microsoft 365 Administrator
- Ran contract and quarterly penetration tests against REST and GraphQL applications; identified and assessed 30+ OWASP Top 10 vulnerabilities and delivered client reports with risk ratings and remediation.
- Administered Microsoft 365 and Apple Business Essentials — Entra ID, Intune, Exchange, SharePoint, OneDrive, Defender, Teams, and Purview.
- Hardened IAM with SAML/SSO, enforced MFA and geo-restrictions, and encrypted endpoints with BitLocker and FileVault.
- Built compliance controls aligned with NIST, SOC 2, PCI-DSS, GDPR, ISO 27001, and CIS, supporting successful client audits.
Internship · Remote
Prompt Engineer
- Applied prompt engineering across AI models to improve application development, code quality, and vulnerability management within the SDLC.
- Analyzed code for vulnerabilities and optimized functions using Python, Golang, and React Native.
- Worked hands-on with GPT-4, DALL·E 2, Copilot, Llama, and Stable Diffusion.
Where I trained.
4.0 GPA · Director’s List
Cybersecurity
- Completed a comprehensive program in penetration testing, cloud security, network security, vulnerability assessment, and secure systems administration.
- Built a pfSense home lab with Snort IDS/IPS; created and competed in CTF events and hosted workshops for classmates.