Skip to main content
Andrew JonesAJ
Open to opportunities

Andrew Jones

@andrewjones1

Senior cybersecurity engineer specializing in offensive security, penetration testing, and AI/LLM red-teaming.

United States
Message

What I'm looking for

I’m looking to lead penetration testing and AI/LLM security research, partner with DevOps and security operations, and help strengthen FedRAMP/SOC 2/ISO 27001 programs—turning findings into clear documentation and actionable remediation.

I’m a U.S. Air Force veteran and Senior Cybersecurity Engineer with 12+ years of experience in offensive security, penetration testing, exploit research, and adversary-focused validation. OSCP-certified, I test internal products and applications using Burp Suite and OWASP ZAP, participate in a corporate bug bounty program, and conduct original AI/LLM red-teaming research.

At SailPoint Technologies, I progressed from Vulnerability Management Engineer to Senior Cybersecurity Engineer, expanding into penetration testing, product security testing, and vendor security evaluation. I designed and optimized the Qualys vulnerability management platform across hybrid cloud and on-premises infrastructure, improving scan coverage and remediation tracking across 20,000+ systems, and I supported first-ever FedRAMP compliance while maintaining SOC 2 and ISO 27001 efforts.

Before that, I delivered incident response and threat hunting as a Cyber Warfare Operator, leveraging the Elastic Stack to aggregate and analyze data and to identify adversary activity. I also served as a Cyber Systems Administrator, using ACAS to scan 20,000 network systems and strengthening security through appropriate countermeasures, STIG/CIS benchmarking, and hands-on forensic and exploit research.

Experience

Work history, roles, and key accomplishments

ST

Senior Cybersecurity Engineer

SailPoint Technologies

Apr 2021 - Jun 2026 (5 years 2 months)

Progressed from Vulnerability Management Engineer to Senior Cybersecurity Engineer, expanding into penetration testing, product security testing, and vendor security evaluation. Performed application and AI/LLM security testing using Burp Suite and OWASP ZAP and supported FedRAMP/SOC 2/ISO 27001 compliance activities.

UF

Cyber Systems Administrator

United States Air Force

Apr 2014 - Feb 2018 (3 years 10 months)

Used ACAS (Assured Compliance Assessment Solution) to scan 20,000 unclassified and classified network systems for security vulnerabilities. Administered servers and other systems, analyzed risk to implement security countermeasures, and supported project delivery with cross-functional teams.

Education

Degrees, certifications, and relevant coursework

CN

CNO-QC

Offensive Cyber Operations

Completed Offensive Cyber Operations training in San Antonio in 2019 through CNO-QC.

CF

Community College of the Air Force

Associate of Science, Cyber Warfare Operations

Earned an Associate of Science in Cyber Warfare Operations in 2018 through the Community College of the Air Force.

CF

Community College of the Air Force

Associate of Science, Cyber Systems Operations

Earned an Associate of Science in Cyber Systems Operations in 2018 through the Community College of the Air Force.

I

39 IOS

Cyber Warfare Operations

Completed Cyber Warfare Operations training in San Antonio in 2018 through 39 IOS.

WU

Western Governors University

IT Security

Completed some IT Security training coursework at Western Governors University without earning a degree.

Root9B logoRO

Root9B

Applied Cyber Operations

Completed Applied Cyber Operations Training in San Antonio in 2018 through Root9B.

Tech stack

Software and tools used professionally

Get matched with your dream remote job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan