Skip to Main Content
All Trimarc services are now delivered through TrustedSec! Learn more

Costa Petros

Senior Security Consultant

EXPERIENCE
Costa Petros began his IT career by covering many facets from the ground up. While in college studying construction management, Costa’s ability to communicate, problem-solve, and collaborate awarded him his first job in IT as a dial-up Internet technical support representative.

As his career progressed, he worked his way up through technical and operational support, PC and IT infrastructure administration, compliance, and consulting roles. Costa held a position as an IT administrator at a branch of a publicly traded company that focused on reselling both Cisco and security services. Costa’s communication skills, technical aptitude, and ‘security-first’ approach opened the door to becoming a penetration tester consultant. As a penetration tester at TrustedSec, Costa specializes in social engineering and physical security assessments. He approaches his work with a ‘hope for the best, prepare for the worst’ mentality.

EDUCATION & CERTIFICATIONS

  • GIAC Penetration Tester (GPEN)
  • Microsoft Certified Professional (MCP)
  • VMware VCA-DCV

PROFESSIONAL AFFILIATIONS

  • InfraGard Northern Ohio Chapter

INDUSTRY CONTRIBUTIONS

  • DerbyCon staff and security, 2017-19

PASSION FOR SECURITY
Costa’s passion for security was evoked at a young age. Growing up in the family takeout business, Costa was taught to protect what you have. This meant locking up at all hours of the day at the family business and at home. As a kid, running in and out of the house was frustrating when he found the doors locked. It didn’t take long for him to find other ways into the house, sometimes climbing onto the roof to bypass a window lock. A curious boy, Costa constantly took apart household items in order to fix, understand, and improve them. This curiosity, his ‘prepare for the worst’ mentality, and ‘protect what you have’ focus drive him to understand and further advance secure implementations.

Featured Blogs And Resources

Discover the blogs, analysis, webinars, and podcasts by this team member.

Blog April 19 2018

It Was the "Summerof2018" - Password Auditing for Windows Administrators

You can audit your Windows domain to identify weak passwords, such as Summer2018 or , and mitigate password spraying by extracting and cracking NTLM hashes…

Read about this article
Webinars January 14 2026

Tips for Incident Response Planning: Prepare Before Crisis Strikes

During our next webinar, our Incident Response experts will cover what organizations should do to prepare so they can respond quickly and be on the way to…

Read about this article
Business Resources December 30 2025

Inside the Modern Red Team: How Attackers Think, and What Defenders Miss

Discover how modern Red Teams think like attackers, what defenders often miss, and how to strengthen your cybersecurity posture.

Read about this article
Blog December 18 2025

Limiting Domain Controller Attack Surface: Why Less Services, Less Software, Less Agents = Less Exposure

Before we dive in, let’s get all the TrustedSec Certified Absolutes out of the way:All software presents some level of inherent risk.Only required software…

Read about this article
News December 17 2025

News 5 Cleveland - Elyria Police responded to a reported restaurant robbery. But it was actually an AI prank.

AI quality is evolving rapidly, making it easier than ever to create convincing fakes from a phone. Advisory Solutions Director Alex Hamerstone spoke with News…

Read about this article
Blog December 16 2025

Top 10 Blogs of 2025

Everyone has a year-end list, and this is ours. See what our top-performing cybersecurity blogs were in 2025, there could be some you might have missed!

Read about this article
News December 13 2025

News 5 Cleveland - Holiday Warning: Keeping your loved ones safe from scams

As the holidays approach, the most effective defense against fraud is an informed family. Advisory Solutions Director Alex Hamerstone spoke with News 5…

Read about this article
News December 12 2025

Security Advisory: React2Shell (CVE-2025-55182) - Critical RCE Vulnerability

A critical vulnerability affecting React Server Components (RSC) is being actively exploited. Here's what to look for and what to do next.

Read about this article
News December 11 2025

WWL First News with Tommy Tucker - Holiday scams are in full swing. Here's how to protect yourself

Don't let scammers ruin your holiday season. Advisory Solutions Director Alex Hamerstone joins WWL First News to discuss the most common seasonal scams and…

Read about this article
Blog December 09 2025

Holy Shuck! Weaponizing NTLM Hashes as a Wordlist

Password reuse is common in Active Directory (AD). From an attacker’s perspective, it is a reliable path to lateral movement or privilege escalation. Most IT…

Read about this article

Empower your business through better security design.

Talk directly with our experienced advisory consultants to learn how we can help.