Working Theory

Résumé

Offensive security engineer and former ISSM. A career that runs from Marine counterintelligence, through building and securing federal aviation systems — part of it as an ISSM — to breaking web apps and AI guardrails today.

Baltimore, MD  ·  contact@michaelhixon.com  ·  github.com/MichaelHixon

Experience

Senior Web Application Security Engineer / Penetration Tester 2020 — Present
Independent Consultant

Penetration testing and vulnerability assessment for financial systems and FAA websites; application-security consulting for government and commercial clients.

Application Security Lead · Acting ISSM (2011–2014) 2004 — 2020
Network Designs · FAA Office of Public Affairs

Owned the security posture of 1,000+ hosts, led a 10-person development team, and trained 200+ federal developers in application security. Served as acting ISSM from 2011 to 2014 — the accountable seat, deciding what risk was acceptable and signing my name under it.

Founder & CEO 2013 — 2015
Apptitude, LLC

Built and ran a security SaaS delivering enterprise vulnerability scanning.

Lead Web Engineer 2000 — 2004
RS Information Systems · FAA

Lead engineer and administrator for FAA public websites.

Web Developer 1999 — 2000
Vista RMS

Clients included CareerBuilder.com and the American Red Cross.

Web Developer 1999
Booz·Allen & Hamilton

Clients included the CIA, NSA, and NRO.

Counterintelligence Agent (0211) · Certified Counterterrorism Instructor 1997 — 2000
U.S. Marine Corps Reserve

Human-side security — the part of the trade about the person who talks their way past the lock.

Close Protection 1996 — 1997
Personal detail for John Kluge (Metromedia)
U.S. Marine — Active Duty 1992 — 1996
Security Forces (8152) · Rifleman (0311)

Started in Marine Security Forces (MOS 8152) on a presidential protection detail, then served as an infantry rifleman (0311); deployed on the USS Kearsarge maiden voyage.

Credentials

Writing & Community

← All writing