I'm a red teamer.
I used to document security controls. Now I test them in the real world.
Spending years in Internal Audit and Cyber Security GRC taught me how security controls are supposed to work. Red teaming teaches me how they actually do.
Currently deep into AI security testing, web application security, and building small tools that make the work faster and easier to communicate.
▋

About
The scenic route
into security.
My career started in audit. I ended up in red teaming. What a pivot!
Years of GRC gave me a perspective — I understand how defences are designed. But I got curious about the other side. How do controls actually hold up when someone's trying to break them?
I care about learning, building useful things, and making security feel less like a checkbox and more like something that actually matters. And I'm genuinely loving every bit of it.
“First, learn the rules. Then break them.”
Timeline
The journey so far
2020 – 2021
Internal Audit
Worked with a LOT of spreadsheets. Learned how governance, risk, controls, and evidence fit together.
2022
IT Auditing
Got curious about the tech. Started digging into information systems, access controls, and infrastructure.
2023 – 2026
Cybersecurity GRC
Learned a lot about policies, frameworks, and controls. Lots of security reviews, assessments, and risk conversations.
2026
Red TeamNOW
The fun part — switched sides of the checklist. Now I get to test the controls instead of reviewing them.
Next
Still learning.
The best chapter so far.
2020 – 2021
Internal Audit
Worked with a LOT of spreadsheets. Learned how governance, risk, controls, and evidence fit together.
2022
IT Auditing
Got curious about the tech. Started digging into information systems, access controls, and infrastructure.
2023 – 2026
Cybersecurity GRC
Learned a lot about policies, frameworks, and controls. Lots of security reviews, assessments, and risk conversations.
2026
Red TeamNOW
The fun part — switched sides of the checklist. Now I get to test the controls instead of reviewing them.
Next
Still learning.
The best chapter so far.
Background
Education
The degrees where it all started.
University of Pretoria
·2015 – 2017
Long before cybersecurity, this is where I learned the language of business, risk, and controls.
University of Pretoria
·2018
Learned how to evaluate whether controls exist, work as intended, and support business objectives.
Credentials
Certifications & Learning
A mix of governance, auditing, AI security, and offensive security — which pretty much sums up my journey so far.
Practical AI Pentesting Associate
TCM Security
AI security, prompt injection, model exploitation
Certified Information Systems Auditor
ISACA
IS audit, control assessment, governance
Certified Internal Auditor
IIA
Internal audit standards, risk, and governance
Junior Penetration Tester
eLearnSecurity
Network pentesting, exploitation fundamentals
Web Application Penetration Tester
eLearnSecurity
Web app attacks, OWASP, API testing
Practical Junior Penetration Tester
TCM Security
Network pentesting, Active Directory, internal assessments
CompTIA Security+
CompTIA
Security fundamentals, risk management, cryptography
Work
Featured Projects
Things I'm building — documentation and GitHub links coming soon.
ChatTrace
An AI security testing workspace — prompt generation, test tracking, findings documentation, and automated reporting. Coming soon.
Active Directory Lab Notes
A living collection of notes from studying AD enumeration, attack paths, and internal network testing. Documentation in progress.
Pentest Reporting Templates
Clean reporting templates built from my GRC background. Designed for clear technical and business communication. Coming soon.
Coming Soon
documenting as we speak...
Fun facts
The non-security part of the CV.
Things I optimise
Things that make me happy
Current hyperfixation
Whatever I'm learning
right now.
Outside work
Get in touch
Let's build something secure.
Always happy to connect about cybersecurity, red teaming, AI security, learning, or cool projects.
Thanks for stopping by :)
Stay curious. Stay cool.
— Simone