Leo Smith

Full Spectrum Operator | Red Team & Physical Access | Custom Tooling | leosmith.wtf

Austria

About

Cyber Security researcher whose main focus is pen-testing. Helped companies save over 100 thousand euros all across Europe through developing pen-testing and red teaming capabilities. With my experience I am equipped with the ability to test your infrastructure and assist you in keeping your assets safe.

Experience

  • Lead Internal Penetration Tester at MM Group
    Dec 2022 - Present · 3 yrs 7 mos

    Built the penetration testing capability from the ground up — saving the company over €300k yearly by internalizing what was previously outsourced. - Physical access and social engineering assessments - Vulnerability assessments on partners strengthening business relationships - Executive level reporting that expanded team bookings company wide - Mentored team members increasing monthly test throughput

  • Penetration Tester at BSI
    Jul 2022 - Sep 2022 · 3 mos

    - Full engagement lifecycle from kick-off to wash-up calls - Report writing focused on executive and technical audiences - Applied security research skills to real client environments

  • SOC Analyst & Web Application Penetration tester at Huawei
    Jul 2021 - Jun 2022 · 1 yr

    Automated SOC operations reducing a 4-person workload to a single operator. - Web application penetration tests on internal Huawei development portals - Saved thousands in external pentest costs by running assessments internally - Built the foundation for internal red team capabilities alongside SOC responsibilities

  • Red Team at Synack Red Team
    Oct 2020 - Sep 2021 · 1 yr

    Bug bounty style web application testing defending clients including Aylo, Dominos, and VARO Money. - OWASP Top 10 expertise developed across high security targets - Operated against advanced threat actors on hardened production systems - Contributed to global security through continuous assessment format

  • Freelance Security Consultant at Malt
    Sep 2020 - Jul 2021 · 11 mos

    Independent security consultant serving SMEs across Paris — web audits, DDoS incident response, and basic forensics. - Helped clients prioritize security spend through threat landscape assessments - Incident response during active DDoS attacks including authority liaison - Asset recovery support post cyber attack