Offensive security engineer and former ISSM. A career that runs from Marine counterintelligence, through building and securing federal aviation systems — part of it as an ISSM — to breaking web apps and AI guardrails today.
Baltimore, MD · contact@michaelhixon.com · github.com/MichaelHixon
Experience
Penetration testing and vulnerability assessment for financial systems and FAA websites; application-security consulting for government and commercial clients.
Owned the security posture of 1,000+ hosts, led a 10-person development team, and trained 200+ federal developers in application security. Served as acting ISSM from 2011 to 2014 — the accountable seat, deciding what risk was acceptable and signing my name under it.
Built and ran a security SaaS delivering enterprise vulnerability scanning.
Lead engineer and administrator for FAA public websites.
Clients included CareerBuilder.com and the American Red Cross.
Clients included the CIA, NSA, and NRO.
Human-side security — the part of the trade about the person who talks their way past the lock.
Started in Marine Security Forces (MOS 8152) on a presidential protection detail, then served as an infantry rifleman (0311); deployed on the USS Kearsarge maiden voyage.
Credentials
Writing & Community