Jake Mayhew

DevOps Engineer

Pittsburgh, Pennsylvania, United States9 yrs 2 mos experience
Highly Stable

Key Highlights

  • Expert in offensive security and penetration testing
  • Led training at prestigious conferences like BlackHatUSA
  • Passionate about cybersecurity knowledge sharing
Stackforce AI infers this person is a Cybersecurity Specialist with a focus on Offensive Security and Penetration Testing.

Contact

Skills

Core Skills

Penetration TestingNetwork SecurityWeb Application Security AssessmentRed Teaming

Other Skills

Technical WritingDisable DeviceStealthVulnerability AssessmentExploit developmentVulnerability ResearchEvasionCobalt StrikeElastic Stack (ELK)Threat HuntingThreat DetectionSense MotiveTacosOxford Comma

About

Jake is an experienced cybersecurity professional with a particular emphasis on offensive security, especially internal & assumed breach penetration tests. In addition to several years in consulting performing penetration tests & offensive security engagements for clients in a wide range of industries, he has also led internal red teams. He currently serves as the Director of Offensive Operations at White Knight Labs, a bespoke offensive security consulting company. He enjoys diving deep into vulnerabilities and researching new ways to bypass the latest detection tools. Currently, he focuses on researching ways to overcome EDR technologies using vulnerable drivers and kernel mode attacks. He is also interested in blue team concepts: how to detect, respond to, and defend against the offensive techniques he leverages. Jake has a strong passion for imparting cybersecurity knowledge to others. He has led or co-led trainings for courses at prestigious industry conferences such as BlackHatUSA including the PEN-200 (OSCP) class, and currently teaches the WKL Offensive Development course at top security conferences. On a daily basis, he loves being able to interact with the cybersecurity community through mutual knowledge sharing.

Experience

Microsoft

Principal Penetration Tester

Oct 2025Present · 5 mos · United States · Remote

  • Penetration testing lead for Microsoft Security Pentest & Automation Team (MSPAT). We perform testing on Microsoft Security products & services including: Purview, Microsoft Defender for Endpoint, Intune, etc.
Penetration TestingTechnical WritingNetwork Security

White knight labs

Director of Offensive Security Operations

Feb 2025Oct 2025 · 8 mos · Greater Pittsburgh Region · Remote

  • Execution Lead: Scope and perform offensive security engagements including red teaming, internal/external penetration tests, cloud, web, mobile, etc.
  • Research & Innovation: Drive R&D initiatives in EDR security and Windows internals. Discovered vulnerabilities and wrote exploits for multiple Windows driver 0-days.
  • Training & Content Development: Develop technical content and deliver offensive security talks and trainings both remotely and at infosec conferences.
  • Operational & Team Leadership: Mentor and guide a team of consultants and offensive security engineers.
Red TeamingPenetration TestingExploit developmentWeb Application Security Assessment

Synack red team

Security Researcher

Nov 2023Mar 2024 · 4 mos · Remote

Upmc

2 roles

Offensive Security Analyst, Senior

Promoted

Mar 2023Feb 2025 · 1 yr 11 mos · Remote

  • I lead UPMC's Red Team, executing offensive security engagements such as red team engagements, infrastructure penetration tests, web app pentests, purple team engagements, and PCI pentests. I also do research into evasion & stealth practices including EDR evasion.
  • Infrastructure penetration testing & red teaming
  • Offensive capabilities development & EDR research (C, C++, scripting)
  • Web application security & penetration testing
  • Active Directory security
Web Application Security AssessmentTechnical WritingDisable DeviceNetwork SecurityStealthPenetration Testing+1

Senior Vulnerability Management Analyst

Nov 2021Mar 2023 · 1 yr 4 mos · Remote

  • Lead red team & offensive security activities: penetration tests, red team engagements, "purple" team activities working with SOC, compliance testing, etc.
  • Application security: web application assessments & scanning with Burp Pro/Enterprise and AppScan, investigating results, communicating issues to app owners and consulting on remediation
  • Vulnerability assessment & management activities: manual vulnerability analysis & identification, scripting, assisting in Rapid7 Nexpose/InsightVM scanning activities
  • Training: mentor vuln team members and cross-train other teams in technical cybersecurity skills
Web Application Security AssessmentTechnical WritingDisable DeviceNetwork SecurityStealthPenetration Testing+1

Applied technology academy

Senior Instructor (Offensive Security)

Mar 2023Mar 2025 · 2 yrs · Hybrid

  • I currently provide instructor-led training and course development for technical cybersecurity courses to help students prepare for certification exams such as the industry-leading OSCP (OffSec Certified Professional) and OSED (OffSec Exploit Developer).
  • I have played a key role in content development for the PEN-200 OSCP course as well as led the content development for the EXP-301 OSED course including custom lab development. I am currently working on developing content for the PEN-300 OSEP course as well.

Virtualprotect, llc

Owner & Principal Security Consultant

Aug 2021Present · 4 yrs 7 mos · Pittsburgh, Pennsylvania, United States

  • Security consulting: penetration testing (infrastructure, web app, PCI, red team), security architecture, training, forensics, etc.
  • Offensive security training
Web Application Security AssessmentTechnical WritingDisable DeviceNetwork SecurityStealthPenetration Testing+1

Payment software company - psc

Security Consultant, Penetration Tester

Apr 2020Nov 2021 · 1 yr 7 mos · Remote

  • Infrastructure and web application penetration testing.
  • Internal pentests
  • External pentests
  • Web application pentests
  • Mobile application pentests
  • PCI pentests
Web Application Security AssessmentTechnical WritingDisable DeviceNetwork SecurityStealthPenetration Testing+1

Seiso, llc

Red Team Consultant

Jan 2019Apr 2020 · 1 yr 3 mos

  • Offensive security consulting including infrastructure & network pentesting, exploit development, web application pentesting & souce code review, and adhoc hacking things for clients.
Web Application Security AssessmentTechnical WritingDisable DeviceNetwork SecurityStealthPenetration Testing+1

Hm health solutions

Emerging Leaders Program Associate

Jan 2017Jan 2019 · 2 yrs

  • Completed four rotations: Cyber risk management, Linux system administration, network engineering, and red team.
  • I performed offensive security tests, including: wireless and infrastructure penetration tests on hospital networks, web application tests, and mobile/medical device penetration tests. I ended up spearheading the development of the Red Team, supporting the vulnerability management & application security team.
Web Application Security AssessmentDisable DeviceNetwork SecurityPenetration TestingVulnerability Assessment

Mylan

Threat Intelligence & Incident Response Intern

May 2016Jan 2017 · 8 mos · Greater Pittsburgh Region

  • Threat intelligence custom tool development, phishing incident response.
Network SecurityPenetration Testing

Education

Robert Morris University

Bachelor of Science - BS — Cyberforensics and Information Security

Dec 2016Present

Stackforce found 100+ more professionals with Penetration Testing & Network Security

Explore similar profiles based on matching skills and experience