Skip to Main Content
All Trimarc services are now delivered through TrustedSec! Learn more

Costa Petros

Senior Security Consultant

EXPERIENCE
Costa Petros began his IT career by covering many facets from the ground up. While in college studying construction management, Costa’s ability to communicate, problem-solve, and collaborate awarded him his first job in IT as a dial-up Internet technical support representative.

As his career progressed, he worked his way up through technical and operational support, PC and IT infrastructure administration, compliance, and consulting roles. Costa held a position as an IT administrator at a branch of a publicly traded company that focused on reselling both Cisco and security services. Costa’s communication skills, technical aptitude, and ‘security-first’ approach opened the door to becoming a penetration tester consultant. As a penetration tester at TrustedSec, Costa specializes in social engineering and physical security assessments. He approaches his work with a ‘hope for the best, prepare for the worst’ mentality.

EDUCATION & CERTIFICATIONS

  • GIAC Penetration Tester (GPEN)
  • Microsoft Certified Professional (MCP)
  • VMware VCA-DCV

PROFESSIONAL AFFILIATIONS

  • InfraGard Northern Ohio Chapter

INDUSTRY CONTRIBUTIONS

  • DerbyCon staff and security, 2017-19

PASSION FOR SECURITY
Costa’s passion for security was evoked at a young age. Growing up in the family takeout business, Costa was taught to protect what you have. This meant locking up at all hours of the day at the family business and at home. As a kid, running in and out of the house was frustrating when he found the doors locked. It didn’t take long for him to find other ways into the house, sometimes climbing onto the roof to bypass a window lock. A curious boy, Costa constantly took apart household items in order to fix, understand, and improve them. This curiosity, his ‘prepare for the worst’ mentality, and ‘protect what you have’ focus drive him to understand and further advance secure implementations.

Featured Blogs And Resources

Discover the blogs, analysis, webinars, and podcasts by this team member.

Blog April 19 2018

It Was the "Summerof2018" - Password Auditing for Windows Administrators

You can audit your Windows domain to identify weak passwords, such as Summer2018 or , and mitigate password spraying by extracting and cracking NTLM hashes…

Read about this article
Webinars April 15 2026

You Had Us at the First Alert: A Guide to Finding Frequently Missed Detections

Join us for this webinar to get a clearer picture of where your detection coverage has blind spots and a practical roadmap for closing them before a real…

Read about this article
Events TrustedSec HQ | March 31 2026

ISC2 Cleveland Chapter Member Meeting - March 2026

ISC2 Cleveland Chapter March MeetupCome join us for our meetup! The ISC2 Cleveland Chapter is hosting an exciting in-person event for all cybersecurity…

Read about this article
Blog March 26 2026

Policy as Code: Stop Writing Policies and Start Compiling Them

The Problem Nobody Wants to Talk AboutLet me paint a picture most security leaders will recognize.You have 30+ policies living as Word documents on SharePoint.…

Read about this article
Podcasts March 24 2026

Security Noise - AI is Exploring The Deep Blue CVEs

On this episode of Security Noise, we explore the cutting-edge use of AI in vulnerability research, exploit development, and cybersecurity defense with guests…

Read about this article
Blog March 24 2026

Building a Detection Foundation: Part 4 - Sysmon

Filling the Gaps Native Logging Can'tAt this point in our series, we have Windows Security events capturing logon sessions and process creation, and…

Read about this article
News March 20 2026

ABC7 Chicago - March Madness betting, ticket scams targeting college basketball tournament fans

March Madness is in full swing and so are the scams, the latest being fake tickets sales and "bogus" bracket challenges. Advisory Solutions Director Alex…

Read about this article
Events March 19 2026

Discord Livestream - AMA: Incident Response

Ask us anything about incident response! Join us for an exclusive Discord Livestream with IR Practice Lead Ryan Macfarlane.

Read about this article
Blog March 19 2026

Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

Invisible password sprays. Invisible logins. Full tokens returned.Nyxgeek here. It's 2026 and I've got two more Azure Entra ID sign-in log bypasses…

Read about this article
Webinars March 18 2026

Copilot Security: What to Know Before You Go

In this webinar, our experts will walk you through the critical groundwork needed before deploying Microsoft 365 Copilot. Learn how you can best prepare for…

Read about this article

Empower your business through better security design.

Talk directly with our experienced advisory consultants to learn how we can help.