RootSec

About

Jonathan · RootSec

About Me

I'm Jonathan (rootsec), a penetration tester and CHECK Team Member with extensive experience in offensive security. I specialize in web application security, phishing campaigns, and internal network testing, with particular interests in SAP security, IoT devices, phishing and red team operations.

In my 2 years as a Penetration Tester, I've developed a passion for uncovering complex vulnerabilities and helping organizations strengthen their security posture through comprehensive penetration testing and security assessments.

When I'm not working, I enjoy sharing knowledge through research, developing security tools, and contributing to the cybersecurity community through detailed write-ups and public talks (check out my BSides London 2025 talk).

Career

Aristi

Cyber Security Consultant @ Aristi

Apr 2025 – Present

Involved in various security engagements such as external infrastructure, vulnerability assessments, build reviews, phishing and web application assessments.

Forvis Mazars

Ethical Hacking Consultant @ Forvis Mazars

Sep 2023 – Apr 2025

Responsible for undertaking different types of assessments including web applications, APIs and thick client applications as well as experience with phishing engagements and infrastructure setup for tools such as GoPhish and EvilginX

Forvis Mazars

Ethical Hacking Intern @ Forvis Mazars

Jul 2022 – Aug 2022

Supported colleagues during assesments including OSINT and web applications. Created and ran an Azure hacking CTF and redesigned a penetration test report to better convey findings and results of the assessment.

Info

role : Penetration Tester
status : CHECK Team Member
focus : Web · Phishing · Internal
based : United Kingdom