Andrew Jones
@andrewjones1
Senior cybersecurity engineer specializing in offensive security, penetration testing, and AI/LLM red-teaming.
What I'm looking for
I’m a U.S. Air Force veteran and Senior Cybersecurity Engineer with 12+ years of experience in offensive security, penetration testing, exploit research, and adversary-focused validation. OSCP-certified, I test internal products and applications using Burp Suite and OWASP ZAP, participate in a corporate bug bounty program, and conduct original AI/LLM red-teaming research.
At SailPoint Technologies, I progressed from Vulnerability Management Engineer to Senior Cybersecurity Engineer, expanding into penetration testing, product security testing, and vendor security evaluation. I designed and optimized the Qualys vulnerability management platform across hybrid cloud and on-premises infrastructure, improving scan coverage and remediation tracking across 20,000+ systems, and I supported first-ever FedRAMP compliance while maintaining SOC 2 and ISO 27001 efforts.
Before that, I delivered incident response and threat hunting as a Cyber Warfare Operator, leveraging the Elastic Stack to aggregate and analyze data and to identify adversary activity. I also served as a Cyber Systems Administrator, using ACAS to scan 20,000 network systems and strengthening security through appropriate countermeasures, STIG/CIS benchmarking, and hands-on forensic and exploit research.
Experience
Work history, roles, and key accomplishments
Senior Cybersecurity Engineer
SailPoint Technologies
Apr 2021 - Jun 2026 (5 years 2 months)
Progressed from Vulnerability Management Engineer to Senior Cybersecurity Engineer, expanding into penetration testing, product security testing, and vendor security evaluation. Performed application and AI/LLM security testing using Burp Suite and OWASP ZAP and supported FedRAMP/SOC 2/ISO 27001 compliance activities.
Cyber Warfare Operator
United States Air Force
Feb 2018 - Mar 2024 (6 years 1 month)
Delivered incident response and threat hunting across customer networks supporting national security operations. Researched and designed computer forensic tools and used the Elastic Stack to aggregate and analyze data to identify adversary activity.
Cyber Systems Administrator
United States Air Force
Apr 2014 - Feb 2018 (3 years 10 months)
Used ACAS (Assured Compliance Assessment Solution) to scan 20,000 unclassified and classified network systems for security vulnerabilities. Administered servers and other systems, analyzed risk to implement security countermeasures, and supported project delivery with cross-functional teams.
Education
Degrees, certifications, and relevant coursework
CNO-QC
Offensive Cyber Operations
Completed Offensive Cyber Operations training in San Antonio in 2019 through CNO-QC.
Community College of the Air Force
Associate of Science, Cyber Warfare Operations
Earned an Associate of Science in Cyber Warfare Operations in 2018 through the Community College of the Air Force.
Community College of the Air Force
Associate of Science, Cyber Systems Operations
Earned an Associate of Science in Cyber Systems Operations in 2018 through the Community College of the Air Force.
39 IOS
Cyber Warfare Operations
Completed Cyber Warfare Operations training in San Antonio in 2018 through 39 IOS.
Western Governors University
IT Security
Completed some IT Security training coursework at Western Governors University without earning a degree.
Root9B
Applied Cyber Operations
Completed Applied Cyber Operations Training in San Antonio in 2018 through Root9B.
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring Andrew?
You can contact Andrew and 90k+ other talented remote workers on Himalayas.
Message AndrewGet matched with your dream remote job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
