Resume¶
Ty Anderson - Remote, CA (open to hybrid)
Full resume and contact info available upon request.
Professional Summary¶
Staff Red Team Engineer with 11 years of offensive security experience and 3 years applying AI to offensive security workflows. Engineers and evaluates autonomous offensive security agents that orchestrate models, tools, and multi-step attack chains to discover vulnerabilities, perform post-exploitation, and validate real-world impact in production environments. Combines deep attacker expertise with agent engineering, security evaluation, and technical leadership to uncover systemic risk and drive durable security improvements.
Work Experience¶
Staff Red Team Engineer¶
Adobe, Remote, CA — Nov 2021 – Present
- Built and operate Adobe's custom Command and Control (C2) platform, used across 20+ red team operations over 5 years to conduct realistic adversarial testing of major production services and enterprise environments
- Integrated AI models into the C2 platform and built a multi-agent orchestrator with specialized agents for reconnaissance, network discovery, credential validation, exploitation, and impact validation, translating expert offensive workflows into autonomous capabilities
- Engineered constrained tooling, technical controls, observability, alerting, human-in-the-loop oversight, and runtime operator steering to make autonomous agent activity safe and controllable in production testing
- Directed an adversarial assessment of enterprise MCP servers that influenced companywide efforts to standardize AI-system security
- Built a multi-agent Red vs Blue system that autonomously discovers vulnerabilities, generates detections, patches findings, and redeploys hardened applications with minimal human intervention
- Co-created Red Team Levels, an attack-chain complexity framework that changed how Adobe measures defensibility and prioritizes security investment
- Led red team operations that identified systemic risk across critical infrastructure and influenced policy, process, architecture, and security-control improvements
Offensive Security Consultant¶
Black Cat Security, Remote, CA — Mar 2024 – Present
- Developed offensive security testing and reporting agents that chain reconnaissance, tool output, and exploit validation, reducing time-to-finding by 75% while expanding practical testing coverage
Security Researcher / Offensive Security¶
Adobe, San Jose, CA — Aug 2019 – Nov 2021
- Researched and uncovered dozens of 0-days in critical authentication flows using Python and Burp Suite, and presented findings and guidance on the public Adobe blog and in large podcasts
- Documented and published prevention and remediation steps to significantly reduce SAML vulnerabilities across the company, and implemented automated regression testing to monitor and maintain secure state across thousands of SSO applications
- Researched and developed Python automation to discover and validate hundreds of subdomain takeovers and implemented preventative and responsive controls to prevent resurgence
Information Security / Vulnerability Management¶
General Motors, Detroit, MI — Jun 2017 – Aug 2019
- Led team of five to harden our external attack surface through scaled identification, validation and remediation of risk
- Developed Python security tools to help identify and remediate dozens of critical database misconfigurations across company, preventing complete exposure of databases
- Automated security scanning pipeline of 10,000+ Oracle DB servers using Python
Information Security / Single Sign-on¶
Qualtrics, Provo, UT — Sep 2015 – May 2017
- Identified and removed cleartext credentials from SSO configuration portals, protecting hundreds of business customer accounts
- Discovered and remediated XSS in main service portal, protecting employees from injection attacks
- Led team of three to successfully configure 300+ SSO (SAML, CAS, LDAP) implementations
Education¶
MS & BS, Information Systems Management — Apr 2017 Brigham Young University, Provo, UT Major GPA 3.67, Total GPA 3.76
Certifications:
- OSCP — Offensive Security Certified Professional
- GWAPT — GIAC Web Application Penetration Tester
- GCIH — GIAC Certified Incident Handler
- GCIA — GIAC Certified Intrusion Analyst
- GSEC — GIAC Security Essentials Certification
- Security+ — CompTIA Security+
- ACE — AccessData Certified Examiner
Selected Publications & Thought Leadership¶
Red Team Strategy Guide Author of an ongoing guide examining the purpose, strategy, and organizational operation of internal red teams, with an emphasis on aligning red team activity with meaningful security outcomes.
Engineering and Evaluating an Autonomous Agent for Post-Exploitation Published research on building and evaluating an autonomous post-exploitation agent.
How to Find and Fix Bugs Using AI Agents Published research demonstrating AI-assisted vulnerability discovery and remediation.
Adobe Security Blog Authored multiple articles on SAML security and AI-assisted red teaming.
Speaking Presented SAML security research at the Department of Homeland Security Monthly Technical Threat Exchange and on industry podcasts; guest speaker in several BYU security classes.