Andrew H.

Co-Founder

West Melbourne, Victoria, Australia18 yrs 10 mos experience
AI EnabledAI ML Practitioner

Key Highlights

  • Co-founder and CTO of an AI cybersecurity startup.
  • Led security operations for major banking institutions.
  • Renowned security researcher with 12k+ GitHub stars.
Stackforce AI infers this person is a Cybersecurity expert with a strong focus on AI and consulting in financial services.

Contact

Skills

Core Skills

CybersecurityArtificial Intelligence (ai)LeadershipConsultingApi SecurityDevsecopsCyber Threat Intelligence (cti)Big DataCryptocurrencyManagement

Other Skills

BitcoinChange ManagementComputer ForensicsComputer SecurityCryptographyCyber UpliftElasticsearchEthereumEvent Driven ProgrammingExit StrategiesGovernment ContractingGraphic DesignIncident AnalysisIncident HandlingInformation Security

About

Andrew Horton is CTO of ThreatCanary, an AI cyber platform startup he co-founded—an autonomous AI platform that discovers zero-day vulnerabilities in APIs that traditional scanners miss. He is a full-stack leader (UX through to assembly) with a strong background in cybersecurity and applies design-thinking to solve complex problems. He performed cyber uplift consulting for Australian banks and assessed Service NSW's susceptibility to an Optus-style data breach—insights that inspired founding ThreatCanary after realizing the API data breach problem was unmet by existing vendors. Andrew was Director of Engineering for CoinPayments, the world's largest cryptocurrency payments provider with 100,000+ web merchants in 200 countries, managing billions in transactions. He's best known for security research with 12k+ GitHub stars across tools like WhatWeb and URLCrazy, integrated into Kali Linux and cited in textbooks, academic papers, and professional methodologies. Andrew advises startups, mentors professionals, speaks at conferences, and recently started briefing strategic policy think-tanks on cyber and AI issues. Through consulting, Andrew has worked with clients in banking, telecommunications, energy, insurance, health, NGOs, and government. He's delivered work for entities managing more capital than many countries' GDPs. He's experienced with compliance and regulatory requirements, including responding to state-backed APT threats against critical infrastructure and managing teams on financial sanctions compliance. His expertise includes penetration testing, reverse engineering, and Kubernetes/container security, UI/UX, and much more. Andrew leads technical teams across the entire stack from UX to network/SRE engineers, retaining staff by cultivating positive work experiences. He bridges business needs with technical requirements, improving collaboration and building resilient team cultures. He provides a clear voice to the exec/board while thriving in dynamic environments with conflicting stakeholder requirements. Andrew is exploring applications of biomimicry, DeSci/longevity research, and the intersectionality of rights at a strategic culture level.

Experience

18 yrs 10 mos
Total Experience
2 yrs 2 mos
Average Tenure
1 yr 3 mos
Current Experience

Threatcanary

2 roles

Co-founder: CTO

Mar 2025Present · 1 yr 3 mos · Melbourne, Victoria, Australia · Remote

  • Starting up. Developing a next-gen cyber product to solve enterprise problems.
StartupsAPI SecurityCybersecurityArtificial Intelligence (AI)Large Language Models (LLM)Event Driven Programming

Co-Founder: CTO

Apr 2023Mar 2025 · 1 yr 11 mos · Melbourne, Victoria, Australia · Remote

  • Working on weekends and in-between contracts

Beyond bank australia

SecOps Manager & SecOps Specialist (Cyber Uplift)

Feb 2024Nov 2024 · 9 mos · Melbourne, Victoria, Australia · Remote

  • Security Operations Manager | Beyond Bank (Cyber Uplift Consulting Project)
  • As part of a comprehensive Cyber Uplift consulting project, I joined Beyond Bank to lead the Security Operations function and drive critical enhancements across the organization’s security posture. Leveraging my extensive expertise in Offensive Security and Penetration Testing, I provided a unique perspective on integrating offensive tactics to strengthen defensive strategies, ensuring the rationale for implementing key security measures was well-understood and impactful.
  • Key Achievements:
  • Successfully conducted a physical red team assessment across offices in three states.
  • Reverse engineered and identified a chain of vulnerabilities to cash out an ATM kiosk.
  • Led initiatives to enhance Cyber team maturity, focusing on:
  • Vulnerability management processes.
  • Email security (DMARC, SPF, DKIM) best practices.
  • Improved SSL/TLS configurations.
  • Built comprehensive team documentation to standardize processes and support knowledge sharing.
  • Spearheaded training and certification programs, enabling the Cyber team to upskill and achieve certifications that aligned with uplift projects.
  • Produced a creative and engaging security awareness video featuring rapping puppets to promote organizational awareness.
  • Managed vendor-led security assessments and personally performed:
  • Red-team-style physical/office security assessments.
  • Penetration tests and security reviews of key technology assets.
  • Collaborated with technology vendors to identify and mitigate vulnerabilities, enhancing overall security resilience.
  • Improved vulnerability management, vastly increasing visibility of vulnerabilities.
  • Improved board and c-level reporting on cyber with actionable insights to drive change.
  • After a dedicated Security Operations Manager was hired, I transitioned into the SecOps Specialist role to continue supporting the uplift project and ensure the seamless implementation of critical initiatives.
CybersecurityChange ManagementLeadershipCyber Uplift

Service nsw

Principal DevSecOps Advisor

Oct 2022Apr 2023 · 6 mos · Melbourne, Victoria, Australia · Remote

  • 6 month contract for the Vulnerability Assessment project to assess SNSW's exposure to an Optus-style data breach of PII (Personally Identifiable Information).
  • Designed and prototyped cloud-native API security management solution.
  • Supported DevSecOps Uplift as part of Cyber Security Resilience and Uplift Program (CSRUP).
  • Reported observations for transformational Cyber uplift.
  • Participated in the security panel for the SNSW Leader's Day event.
API SecurityDevSecOpsPenetration TestingGovernment Contracting

Sonar, inc

Director

Apr 2022Oct 2022 · 6 mos · Melbourne, Victoria, Australia

  • Threat Intelligence startup. Followed CTO out of CoinPayments into Sonar.
ElasticsearchCyber Threat Intelligence (CTI)Big Data

Coinpayments

Director Of Engineering

Oct 2021Apr 2022 · 6 mos · Melbourne, Victoria, Australia

  • CoinPayments was the world's largest cryptocurrency payments provider with over 2m customers in nearly 200 countries.
  • Full-stack manager. Built out a new IT team, developed IT roadmaps, developed project management systems, developed people's skill-sets, managed projects across the entire tech-stack from UX to C code, stayed technical while managing, and looked after my team as best I could. Reported to the CTO.
  • Was consulting to CoinPayments through Path before this in different roles.
  • Followed CTO to Sonar
LinuxCryptocurrencyManagementEthereumProject ManagementBitcoin

Crowd funded cures

Chief Information Officer

Jun 2021Present · 5 yrs · Melbourne, Victoria, Australia · Remote

  • I'm helping Savva Kerdemelidis with this Social Enterprise that may change the world.
  • Outcomes-based financing for open source medicines to prove off-patent therapies work, so we can have affordable medicine for everybody.

Domain defender

Cyber Security Consultant

Sep 2020May 2023 · 2 yrs 8 mos · Melbourne, Victoria, Australia

  • The company I use for consulting. Talk to me about offensive cyber security contracts, penetration testing, brand impersonation, and domain take-downs.
ConsultingCybersecurity

Ayenem

Advisory Board Member and Head of Security

May 2019Jun 2020 · 1 yr 1 mo · Greater Sydney Area

Hacktive

Principal Security Consultant

Jan 2019Oct 2022 · 3 yrs 9 mos · Australia · Remote

  • Hacktive was acquired by Deloitte.
ConsultingWeb Application SecurityCybersecurityPenetration TestingVulnerability Assessment

Hortonsec consulting llc

Director & Principal Cyber Security Consultant

Jan 2019Jul 2020 · 1 yr 6 mos · Dubai, Dubai, United Arab Emirates

  • I am offering offensive security consulting services directly to clients, but the majority of my work is subcontracting for infosec consultancies that need an extra helping hand. My service offerings include external infrastructure and web-app penetration testing. I'm not currently offering mobile or social engineering pentests (despite my experience in these areas).
  • HortonSec is incorporated in the UAE but I'm elsewhere traveling the world while serving the English speaking markets.

Path network

Advisory Board Member and Lead Security Consultant

Oct 2018Oct 2022 · 4 yrs · United States

  • Developed security consulting service-line end-to-end. Created proposal and report templates, did pre-sales, performed security testing, etc. Ensured high quality of security testing and reporting.
ConsultingCybersecurityPenetration TestingPresalesProposal Writing

N/a

World Travel

Jul 2017Jun 2020 · 2 yrs 11 mos · Europe

  • Ask me about all the countries I visited as I travelled round the world with my family! This time wasn't all about climbing volcanoes on horseback in Guatemala, visiting ancient sites like Stonehenge and Chichen Itza, spending time on the beaches of Bali, or flying drones around tropical islands, I also kept up to date with infosec.
  • I extended my skill with ASM and binary reverse engineering. Attended Defcon in Las Vegas, CCC in Leipzig, Crypto meetups in London, HackNYC in New York, 8.8 in Mexico City, and even small OWASP chapter groups in cities like Tbilisi.

Hacklabs

Principal Security Consultant

Oct 2014Jun 2017 · 2 yrs 8 mos · Greater Melbourne Area

  • I can't speak highly enough of my experience with HackLabs. It was a pleasure to work with such a talented team.

Bae systems applied intelligence

Principal Security Consultant

Jan 2012Oct 2014 · 2 yrs 9 mos · Greater Melbourne Area

  • Technical security consulting including penetration testing.
  • Started as a senior consultant.

Security-assessment.com

Security Consultant

Jun 2010Dec 2011 · 1 yr 6 mos · Wellington, New Zealand

  • Penetration testing, developed and delivered training, source code reviews, host reviews, and more.

Morningstar security

Owner

Aug 2009Jun 2010 · 10 mos · Christchurch, New Zealand

  • Security consulting, penetration tests, source code reviews, training, policy development, etc.

Ardent creative

Owner

Mar 2009Jul 2010 · 1 yr 4 mos · Christchurch, New Zealand

  • Web design and web application development.

Printable group

Managing Director

Jan 2003Jan 2009 · 6 yrs · Christchurch, New Zealand

  • Co-founder. Setup business systems, IT, graphic design, bit of everything. Became the dominant digital printing provider in Christchurch, NZ. Did some of the first work in NZ with variable data printing and databases.

Education

University of Canterbury

Bachelor's degree (Incomplete) — Computer Science

Stackforce found 100+ more professionals with Cybersecurity & Artificial Intelligence (ai)

Explore similar profiles based on matching skills and experience