I run security at Ingram, not as a side task, as the actual job. Wrote the guidelines everyone gets onboarded with, picked NIST CSF + Belgium’s CCB Cyfun as the practical starting point instead of jumping straight to ISO 27001, and I’m building the asset inventory and controls we’d need if we go for certification later. Gave an internal presentation on cloud security to the team.
On the hands-on side: pentesting our own product (AI-assisted recon, manual follow-up — the tool’s paying off, results have been good), setting up SSO/MFA with the dev team, picking vulnerability scanning and supply chain tooling — landed on Snyk for supply chain, Greenbone/OpenVAS in evaluation for vulnerability scanning — reviewing AI-generated (“vibe coded”) code for security issues before it ships, and mentoring our security intern.
Old scratch notes this grew out of:
Iso27001
Nist2
Certifications nism csnp
IA
Passion
Cyber what is it
Headmind research
Cloud sec
Read book wim
Rtc internationale
Aspect culturel secu
H4 crak quick w gpu on window
Xss sql
Firewall out reverse
Site find vuln: openvas
Dirbuster
Metasploite
Sqlmap
Greenbone security as
Cia tools
Corelight at home