👨🏻‍💻 Blessen Thomas

Consultant

Wrocław, Dolnośląskie, Poland13 yrs 1 mo experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Over 13 years of experience in cybersecurity.
  • Expert in Red Teaming and Penetration Testing.
  • International speaker at renowned cybersecurity conferences.
Stackforce AI infers this person is a Cybersecurity Expert specializing in Red Teaming and Penetration Testing across various industries.

Contact

Skills

Core Skills

Red TeamingPenetration TestingApplication Security

Other Skills

AS400 Penetration TestingATM Penetration TestingAndroid SecurityApplication Security Architecture ReviewsAutomotive SecurityAzure Penetration TestingAzure Security CentreBluetoothBluetooth Low EnergyBuilding Red Team and pentesting programCC++Cloud Configuration ReviewsContainer & Kubernetes SecurityContainer Security

About

👋🏽 Hi there ! Blessen is a Senior Cyber Security Consultant, Independent Security Researcher,Cyber Security Enthusiast, International Conference Speaker & Trainer,Author, Blogger, Bug Bounty Hunter,Red Teamer & seasoned Penetration Tester, Drummer with a pragmatic approach whose qualifications include 🎓 an Engineering Degree in Information Technology;🏅SANS GPEN,CRTO,OPST,CREST CRT(PEN),CREST CPSA,OSCP,CRTP,OSWP,C)PTE,CEH,CHFI designations; & detailed knowledge of security tools, technologies & best practices.Bug bounty: Synack Red Team (SRT), Bugcrowd, Hackerone 🏆 Invited in world renowned conferences viz. CanSecWest -Vancouver-Canada, OWASP Appsec Europe -Italy ,London-UK ,HITB -Dubai,Hacktivity-Hungary, ROOTCON-Philippines ,OWASP PH,OWASP New Zealand Day, Infosec SouthWest,Austin,Texas, FSec- Croatia, Hackbeach, Hackfest, Shakacon,ITWeb-South Africa, Jordan Cyber Security Summit, HITCON-Taiwan, OWASP Bucharest AppSec-Romania, OWASP Appsec Africa-Morocco, Bsides-London,CircleCityCon,LASCON etc 🏢13+ years of rich experience in the creation and deployment of solutions protecting networks, systems and information assets for various clients & organisations in industrial sectors in Americas, Asia Pacific(APAC),Oceania,Europe(Central Europe,Nordics,DACH),Middle East & Africa(EMEA) region. 🌟Industry verticals: Automotive,Telecom Industry ,Product firms,IT, ITEs,Engineering & Manufacturing,Pharmaceuticals,Banking & Finance Domain/Stock Broking,Investment Authorities,HealthCare/Biomedical Industry,Hospitality & Tourism,Government Sectors,Robotics,Startups,Fintech His areas of interest & expertise include Red Teaming,Attack & Penetration Testing All Things (Offensive Security) 💪🏽 His Skills: - Red/Purple Team Exercises - Adversary Simulation/Emulation Exercises - Red Team Operations & Breach & Attack Simulations - Assumed Breach Assessment - Attack & Penetration Testing Infrastructure, Telecom,USSD (External & Internal). - Appsec (Web, Thick, API & Mobile Apps). - VoIP & Wireless Penetration Testing - Mainframe & legacy systems Penetration Testing - Smart ATMs & KIOSK Penetration Testing - IoT/ Embedded device Penetration Testing - Smart Wearable (iWatch & Android) - SWIFT,RPA,SAP Penetration Testing - Cloud Penetration Testing (AWS,Azure,GCP) - Cloud-native (Kubernetes & Container) - Vulnerability Assessment - fuzzing,reverse engineering & exploit development. - Secure Code Review for web & mobile apps - MDM/MAM implementation review - Security Architecture Reviews & Threat Modelling 🌐📬🐤twitter: @pentagramz 👾📝 github.com/pentagramz/

Experience

Full-time

LeanIX

Present

Ey

13 roles

Senior Cyber Security Consultant

Jun 2025Jun 2025 · 0 mo

  • Pentesting mainframe systems zOS for financial institution.
Pentesting mainframe systemsPenetration Testing

Senior Cyber Security Consultant

May 2025Jun 2025 · 1 mo

  • Leading full-spectrum Red Team operation for critical infrastructure in Belfast, UK
Leading full-spectrum Red Team operationRed Teaming

Senior Cyber Security Consultant

Mar 2025Apr 2025 · 1 mo

  • Performed full-spectrum red team including physical assessments(Black Teaming)
  • Performed POS(Point-of-Sale) IoT device pentesting.
  • Conducting security assessments and penetration tests on automotive embedded systems, such as gateways, connectivity modules, telematics units, and connected vehicle components.
  • Tools:
  • Proxmark3,FlipperZero
  • LAN Turtle, Throwing Star Lan TAP PRO,UbertoothOne
Full-spectrum red team assessmentsPOS IoT device pentestingRed Teaming

Senior Cyber Security Consultant

Nov 2024Nov 2024 · 0 mo

  • Performed Purple teaming - TIBER-DE for one of the well-known bank in Frankfurt,Germany.
  • Regulatory driven Intelligence-led based Testing
  • Sandbox, Email and Web Gateway assessment
  • ART(Advanced Red Teaming)
  • ZORRO for the Healthcare sector: provided by Z-CERT
  • ART for the financial sector: provided by DNB
  • ART for the Government,OSFI I-CRT,Canada,DORA TLPT EU
  • Frameworks: The Unfied Killchain,MITRE ATT&CK,Lockheed Martin CyberKillChain,Diamond Model of Intrusion Analysis,Red Team Maturity Model(RTMM)
Performed Purple teamingRegulatory driven Intelligence-led TestingRed Teaming

Senior Cyber Security Consultant

Nov 2024Nov 2024 · 0 mo

  • Pentesting SWIFT systems for one of the largest bank in Luxembourg based on Customer Security Controls Framework (CSCF) to comply with SWIFT CSP(Customer Security Programme) requirements
Pentesting SWIFT systemsPenetration Testing

Senior Cyber Security Consultant

Oct 2024Nov 2024 · 1 mo

  • Pentesting RPA Bot and performing RPA Security assessment,wireless pentesting for biggest law enforcement entity in Dublin, Ireland
  • Pentesting network infrastructure and OT components for energy provider based on Purdue Model
Pentesting RPA BotWireless pentestingPenetration Testing

Senior Cyber Security Consultant

Sep 2024Oct 2024 · 1 mo

  • Pentesting for biggest railway network in Switzerland based on VATT&EK framework(Vehicle Adversarial Tactics , Techniques & Expert Knowledge)
Pentesting for railway networkPenetration Testing

Senior Cyber Security Consultant

Jul 2024Oct 2024 · 3 mos

  • Building Red Team and pentesting program for one of the biggest security technology company in Switzerland
Building Red Team and pentesting programRed Teaming

Senior Cyber Security Consultant

May 2024Jun 2024 · 1 mo

  • Pentesting Azure cloud infrastructure including landing zones for a public government agency in Ireland.
Pentesting Azure cloud infrastructurePenetration Testing

Senior Cyber Security Consultant

Mar 2024May 2024 · 2 mos

  • Pentesting zOS mainframe system,CICS apps,green terminals for a leading European bank in Gdansk & Gdynia location(tri-city)
Pentesting zOS mainframe systemPenetration Testing

Senior Cyber Security Consultant

Oct 2023Nov 2023 · 1 mo

  • Pentesting mobile apps both android and ios for biggest automotive firm in Sweden
Pentesting mobile appsPenetration Testing

Senior Cyber Security Consultant | Attack & Pen

Sep 2021Present · 4 yrs 6 mos

  • ➤ Red & Purple team assessments, Tabletop Exercises
  • ➤ Penetration testing web/mobile/desktop apps & infra/cloud(AWS,Azure,GCP)
  • ➤ Cloud Configuration Reviews ( AWS, Azure,GCP,OpenShift,AliCloud)
  • ➤ Internal & external pentesting
  • ➤ SAP Penetration Testing including traditional & modern stacks(SAP Fiori,S/4 HANA)
  • ➤ Container & Kubernetes Security
  • ➤ Client and Server Build Reviews
  • ➤ Providing advisory consulting services to clients from various industry verticals in Americas,Europe and Asia region.
  • ➤ Citrix and Locked down Environment Breakouts
  • ➤ Network Device Security Reviews
  • ➤ Firewall Configuration/Rulebase Reviews
  • ➤ Client and Server Build Reviews
  • ➤ Social Engineering (Phishing,vishing)
  • ➤ Physical Security Testing
  • ➤ PCI DSS Penetration Testing
  • ➤ Insider Threat Campaigns
  • ➤ EDR Product Review
  • ➤ OSINT Target Profiling
  • ➤ Knowledge of security and architecture testing and development frameworks, i.e. OWASP, OSSTMM, PTES, ISSAF, &NIST SP 800-115
  • ➤ Regulatory driven Intelligence-led based Testing (DORA-TLPT,CBEST-UK,iCAST-HK,CORIE-AU,TIBER-EU,FINMA Switzerland, FEER-SAMA, TLPT-Japan,AASE-SG,GFMA)
  • ➤ Ransomware Readiness Assessment
  • ➤ Stolen Device Assessment
  • ➤ Remote Access Assessment
  • ➤ Smart Contract Security
  • ➤ Vehicle/IoT/IoMT/ICS Security
  • ➤ Voting machine security
  • ➤ C-UAS Drone Adversarial Testing
  • ➤ Ransomware Readiness Assessment
  • ➤ AI/MCP Pentesting
  • Key Tasks:
  • Led an entire Red Team operation for one of the biggest smart city including OT environment in the world.
  • Infra pentest for highly secured automotive Zabbix environment in Brazil
  • AWS Cloud pentesting for a fintech company in Mexico
  • ATM pentesting for a bank in Bosnia & Herzegovina
  • Blackbox pentesting for a telecom government client in Switzerland
  • SAP,AWS,k8s pentesting for an insurance company in Germany.
  • Red team, table top exercises in sensitive environment for public client in USA
  • Container security for a bank in Singapore
  • Product security pentest in Latvia
Red & Purple team assessmentsPenetration testingCloud Configuration ReviewsSAP Penetration TestingContainer & Kubernetes SecurityRed Teaming+1

Senior Cyber Security Consultant

Sep 2021Apr 2025 · 3 yrs 7 mos

  • Pentesting domotics
  • POS and TMS Security assessment
  • Telecom Signaling Pentest
  • Maritime/Aviation Security Assessment -IACS UR E26, E27, E22 maritime standards
  • Hotel/Hospitality Security Assessment
  • AI/ML/LLM Pentesting - MITRE ATLAS
  • Metaverse Pentesting
  • Pentesting Augmented Reality(AR),Mixed Reality(MR),Extended Reality(XR),Virtual Reality(VR)
  • SDR Pentesting
  • Blockchain Pentesting
  • Telecom Penetration Testing (Air interface and CORE) based on MITRE FiGHT and MOTIF framework
  • Device and hardware Penetration Testing
  • Wireless Security Assessment - OWISAM (Open Wireless Security Assessment Methodology)
  • Red Teaming
  • Super yachts and Marine Penetration Testing
  • Satellite Security assessment SPARTA framework(Space Attack Research & Tactic Analysis)
  • ioT and Firmware Penetration testing
  • IPTV, VOIP, AD exploitation
  • IP-PBX and PSTN Security Assessment
  • Telecom Pentesting
  • VAPT of Telecom Network(EPC & IMS), AppSec ,Architecture Review, Protocol Fuzz Testing(GTP, SIP, SCTP, S1AP, X2AP),SS7,Diameter, GTP,HTTP/2,RAN 2G/4G,5G Core,SIM/eSIM Security assessment,VoLTE & VoWIFI(SIP)
  • Salesforce Pentesting
  • Browser Extensions Security Assessment
  • Railway Penetration Testing ( GSM-R, Wi-Fi, and Ethernet,railway control systems, encompassing signaling systems, communication networks, and train control systems (TCS)
  • Automotive and EV Vehicle Chargers Pentesting
Pentesting domoticsTelecom Signaling PentestPenetration Testing

Ing deutschland

Senior IT Security Engineer

Apr 2021Sep 2021 · 5 mos · Berlin, Germany · On-site

  • Previously Lendico Deutschland GmbH - a brand of ING (acquired by ING Germany)
  • https://www.lendico.de
  • https://www.ing.jobs/germany/person/fintech-meets-direktbank-1.htm
  • Responsible for securing the fintech platform
  • Pentesting infrastructure,applications(Web, API) Cloud and cloud-native ecosystem
  • Red Teaming in Cloud environment:
  • AWS and Azure
  • Cloud native Security Assessments
  • Kubernetes Ecosystem Penetration Testing
  • Container Penetration Testing
  • Red Teaming Assumed Breach Assessments using TTP from MITRE ATT&CK framework
  • In-depth knowledge of relevant information security regulations and standards, including BSI IT Grundschutz,OWASP, NIST, ISO 27001.
  • DevSecOps:
  • SAST:SonarCloud
  • DAST:OWASP ZAP
  • Cloud Security: Prowler,ScoutSuite
  • Cloud-native: tfsec,checkov,clair,trivy,anchore,Checkmarx KICS
  • Azure DevOps
Securing fintech platformPentesting infrastructurePenetration Testing

Sap

Security Engineer

Oct 2019Mar 2021 · 1 yr 5 mos · Bonn, North Rhine-Westphalia, Germany · Hybrid

  • previously LeanIX GmbH (now acquired by SAP)
  • https://news.sap.com/2023/11/sap-completes-acquisition-of-leanix/
  • LeanIX, an SAP company, is a market leader for enterprise architecture management (EAM), driving the modernization of IT landscapes and continuous business transformation. Its software-as-a-service solutions empower organizations to create transparency, enabling them to visualize, assess and manage the transition towards their target IT architecture. LeanIX serves over 1,000 companies globally across various industries, including more than 10% of the Fortune 500 and half of the German DAX 40.

Ocbc bank

2 roles

AVP- Cyber Security Specialist

Promoted

Jun 2019Sep 2019 · 3 mos

AVP - Cyber Security Specialist (TISO)

Apr 2019May 2019 · 1 mo

  • Worked with the Technology Information Security Office - TISO
  • Performed application penetration testing on web based application and thick-client application.
  • API , SOA, Microservices , Container Security Assessment
  • Security Design Reviews
  • Smart ATM Security Assessment using IoT MQTT protocol(MQTT.fx)
  • Application penetration testing of Near Field Communication (NFC) based
  • card-less money(QR code scanning) withdrawal from ATM
  • Cash Dispensers, Cash Machines Security Assessment
  • KIOSK Penetration Testing
  • Smart Boards Security Assessment
  • Legacy systems such as Mid-range Systems (AS400/ IBM iSeries) Penetration Testing
  • HP Tandem NonStop Systems Security Assessment
  • Infrastructure Penetration Testing
  • Perform mobile application penetration testing across different mobile platforms
  • Perform network penetration testing on systems.
  • Exploit vulnerabilities to gain access, and expand access to remote systems.
  • Document technical issues and recommend mitigation controls identified during security assessments.
  • Research cutting edge security topics and new attack vectors
  • Conduct compliance testing on web based application, mobile applications and thick/thin-client application that meet predetermined technology
  • Security Standards and other regulatory requirements such as MAS TRMG.
  • Conduct secure code review and design review of applications.(RPG, C#, Java ,Swift)
  • Conduct Internal Security Trainings
  • DevSecOps :
  • SAST :HP Fortify, Coverity ,Synopsys Black Duck
  • DAST: IBM Appscan, Acunetix

Ey

13 roles

Senior Security Consultant

Oct 2018Oct 2018 · 0 mo

Securing ShipsApplication Security Architecture ReviewsApplication Security

Senior Security Consultant

Promoted

Sep 2018Dec 2018 · 3 mos

  • Securing Ships: In the role of Security Architect, performed secure SDLC activities like Threat Modelling, SAST and DAST and integrated
  • security into a CI/CD workflow for a cruise ship in Miami & Miramar locations,Florida-USA as part of digital transformation for seamless boarding.
  • Reviewed penetration testing reports and provided a mitigation strategy in first place (left
  • shifting).
  • Performed Application Security Architecture Reviews & implemented security in
  • DevSecOps Environment.
Web Application Penetration TestMobile Penetration TestPenetration Testing

Senior Security Consultant

Aug 2017Sep 2017 · 1 mo

Information Security Consultant

Apr 2017Apr 2017 · 0 mo

  • - Performed internal network penetration testing and vulnerability assessment for a leading European bank in Singapore

Senior Security Consultant | Attack & Pen

Oct 2016Mar 2019 · 2 yrs 5 mos

  • Member & SME of the Attack and Penetration Testing Cyber Security Team working full-time as Senior Security Consultant in EY where he delivers Web Application Penetration Test, Mobile Penetration Test (iOS ,Android,Windows,Blackberry,Symbian,UWP platform), Vulnerability Assessment and Network Penetration Test for several enterprise companies and financial institutions worldwide.
  • Collaborated with ASC (Advanced Security Centre) in Australia, Singapore, Israel, Poland, Ireland.
  • Executed numerous Mobile,Web,Thick client Application,Network Penetration Testing for clients in USA,Australia,Germany,Austria,Singapore,Middle East (Jordan,Saudi Arabia,Abu Dhabi,Bahrain,Oman), Zimbabwe,Sudan,Ghana,Mauritius,Egypt, Mozambique, Hong Kong, Kazakhstan.
  • Areas of Expertise :
  • Attack and Penetration Testing
  • Mobile Application (Android, iOS,Blackberry,Windows,Symbian,UWP,J2ME)
  • Smart Watch Wearable Application(Apple Watch, Android Wearable)
  • IoT - Zigbee & Bluetooth Low Energy Protocol using Ubertooth One & Atmel RzRaven USB Stick
  • Web and Thick client (Rich Client) Application
  • Web Services,API (RESTful/WADL ,SOAP/WSDL)
  • SAP & Cloud Application ( AWS ,Microsoft Azure) -SaaS,PaaS,IaaS based Testing
  • Wireless / Software Defined Radio -SDR/RF analysis using RTL-SDR, Yard Stick One, Wifi Pineapple nano
  • Firmware Analysis/Embedded Software Security
  • Network Discovery
  • VOIP/IVR
  • USSD(Unstructured Supplementary Service Data)
  • Infrastructure
  • Social Engineering Assessments & Phishing
  • Host based Vulnerability Assessments
  • Blockchain Application Penetration Testing
  • GSM 2G ,GRX Router,GGSN(Gateway GPRS Support Node),SGSN(Serving GPRS Support Node)
  • Secure Code Review (PHP,android & iOS)
  • Application Security Architecture/Design Reviews
  • DevSecOps -CI/CD process - SAST,DAST
  • Threat Modelling
  • Corporate Cyber Profiling -OSINT
  • Configuration Reviews & Minimum Security Baseline (MSB) documents
  • International Trainer & Speaker
  • Client discussion & Consultation

Senior Security Consultant

Oct 2016Nov 2016 · 1 mo

Information Security Consultant

Jul 2016Aug 2016 · 1 mo

  • - Performed web,mobile(iOS and android) and thick client penetration testing for a big4 bank in Australia.

Information Security Consultant

Mar 2016Apr 2016 · 1 mo

Information Security Consultant

Aug 2015Sep 2015 · 1 mo

Information Security Consultant

Aug 2015Sep 2015 · 1 mo

Information Security Analyst

Aug 2015Sep 2015 · 1 mo

Information Security Consultant

Jul 2015Aug 2015 · 1 mo

Information Security Analyst

Aug 2013Sep 2016 · 3 yrs 1 mo

  • Key Tasks:
  • Performed External Application & Network Penetration Testing for multiple locations across the globe for the biggest Robotics firm in Germany( DACH region)
  • Performed Thick client and Web Services Penetration Testing for a reputed government regulatory organization in Austria.
  • Performed configuration reviews (OS, Database,Firewall) for various clients in Middle East
  • Performed Network Penetration Testing for the following clients:
  • Large Pharmaceutical company in Saudi Arabia.
  • Reputed consulting organisation in Jordan.
  • SAP & Wireless Penetration Testing for an Internet Service Provider
  • Blockchain Application Penetration Testing for a marine insurance company in UK
  • Performed Amazon AWS Cloud Security Assessment for a client in Middle East
  • Performed Payment Gateway Application Penetration Testing for a largest bank in Abu Dhabi
  • Served as consultant in pre-sales, including assessment of client needs, project scopes and proposal presentation

Kdg technologies

Ethical Hacking Faculty

Jun 2012Jun 2013 · 1 yr · Mumbai Area, India

  • Conduct hands-on training on ethical hacking for students and update the syllabus .
  • Counsel the students on career opportunities
  • Regular maintenance of configuration required for training.

Education

La Salle BCN

OPST ISECOM

Nov 2022Dec 2022

OPST ISECOM - La Salle-URL(Universitat Ramon llull) University

OSSTMM Professional Security Tester

Nov 2022Dec 2022

Universitat Ramon Llull

OPST ISECOM

Nov 2022Dec 2022

Anna University Chennai

Engineer’s Degree — Information Technology

Jan 2007Jan 2011

TeamLogics

High School Diploma — Science

Jan 2005Jan 2007

Stackforce found 100+ more professionals with Red Teaming & Penetration Testing

Explore similar profiles based on matching skills and experience