I'm a red teamer.

I used to document security controls. Now I test them in the real world.

Spending years in Internal Audit and Cyber Security GRC taught me how security controls are supposed to work. Red teaming teaches me how they actually do.

Currently deep into AI security testing, web application security, and building small tools that make the work faster and easier to communicate.

Red TeamingPen TestingSecurity ResearchTool BuilderLifelong Learner
simone@kali ~

Simone Jonker

The scenic route
into security.

My career started in audit. I ended up in red teaming. What a pivot!

Years of GRC gave me a perspective — I understand how defences are designed. But I got curious about the other side. How do controls actually hold up when someone's trying to break them?

I care about learning, building useful things, and making security feel less like a checkbox and more like something that actually matters. And I'm genuinely loving every bit of it.

“First, learn the rules. Then break them.”

The journey so far

2020 – 2021

Internal Audit

Worked with a LOT of spreadsheets. Learned how governance, risk, controls, and evidence fit together.

2022

IT Auditing

Got curious about the tech. Started digging into information systems, access controls, and infrastructure.

2023 – 2026

Cybersecurity GRC

Learned a lot about policies, frameworks, and controls. Lots of security reviews, assessments, and risk conversations.

2026

Red TeamNOW

The fun part — switched sides of the checklist. Now I get to test the controls instead of reviewing them.

Next

Still learning.

The best chapter so far.

Education

The degrees where it all started.

BCom Financial Sciences

University of Pretoria

·

2015 – 2017

Long before cybersecurity, this is where I learned the language of business, risk, and controls.

BCom Honours in Internal Auditing

University of Pretoria

·

2018

Learned how to evaluate whether controls exist, work as intended, and support business objectives.

Certifications & Learning

A mix of governance, auditing, AI security, and offensive security — which pretty much sums up my journey so far.

PAPACertified

Practical AI Pentesting Associate

TCM Security

AI security, prompt injection, model exploitation

CISACertified

Certified Information Systems Auditor

ISACA

IS audit, control assessment, governance

CIACertified

Certified Internal Auditor

IIA

Internal audit standards, risk, and governance

eJPTCertified

Junior Penetration Tester

eLearnSecurity

Network pentesting, exploitation fundamentals

eWPTCertified

Web Application Penetration Tester

eLearnSecurity

Web app attacks, OWASP, API testing

PJPTCertified

Practical Junior Penetration Tester

TCM Security

Network pentesting, Active Directory, internal assessments

Sec+Certified

CompTIA Security+

CompTIA

Security fundamentals, risk management, cryptography

Featured Projects

Things I'm building — documentation and GitHub links coming soon.

v1.0

ChatTrace

An AI security testing workspace — prompt generation, test tracking, findings documentation, and automated reporting. Coming soon.

AI SecurityIn Progress
View Project
v1.0

Active Directory Lab Notes

A living collection of notes from studying AD enumeration, attack paths, and internal network testing. Documentation in progress.

Active DirectoryRed TeamComing Soon
View Project
v1.0

Pentest Reporting Templates

Clean reporting templates built from my GRC background. Designed for clear technical and business communication. Coming soon.

ReportingGRCComing Soon
View Project

Coming Soon

documenting as we speak...

The non-security part of the CV.

Things I optimise

Security
Processes
Lasagne recipes

Things that make me happy

A good Cappuccino
Trying new recipes
Capturing flags

Current hyperfixation

Whatever I'm learning
right now.

Outside work

Building puzzles
DIY projects
Collecting new ideas

Let's build something secure.

Always happy to connect about cybersecurity, red teaming, AI security, learning, or cool projects.

Thanks for stopping by :)

Stay curious. Stay cool.

— Simone