Skip to Main Content

Joe Sullivan

Senior Security Consultant

EXPERIENCE
Joe has over 20 years of experience in Information Security. He has worked in Incident Response, forensics, penetration testing, and security leadership as a CISO for a financial institution.

EDUCATION & CERTIFICATIONS

  • GIAC Penetration Tester (GPEN)
  • GIAC Strategic Planning, Policy, and Leadership (GSTRT)
  • GIAC Certified Forensic Examiner (GCFE)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Security Leadership (GSLC)
  • GIAC Cloud Penetration Tester (GCPN)
  • GIAC Public Cloud Security (GPCS)
  • GIAC Certified Web Application Penetration Tester (GWAPT)
  • Certified Information Systems Security Professional (CISSP)
  • CNSSI 4012 Senior Systems Manager
  • CNSSI 4013 System Administrator in Information Systems Security
  • CNSSI 4014 Information Systems Security Officer
  • NSTISSI 4011 Information Systems Security Professional
  • NSTISSI 4015 Systems Certifier

PROFESSIONAL AFFILIATIONS

  • GIAC Advisory Board, ISC2 

Joe also teaches leadership courses for the SANS Institute.

INDUSTRY CONTRIBUTIONS
Joe has presented at security conferences including Check Point CPX, Information Warfare Summit, and BSides.

PASSION FOR SECURITY
Joe’s passion for security started in Incident Response and forensics in the late ‘90s. Since then, he has developed a passion for offensive security, security leadership, and teaching others.

Featured Blogs And Resources

Discover the blogs, analysis, webinars, and podcasts by this consultant and their team.

Blog July 22 2025

Why is this Finding on my Pentest Report?

Sometimes, one weak link is all it takes. In this blog, Joe Sullivan explains why even seemingly minor findings matter to help highlight best practices,…

Read about this article
Blog March 27 2025

Getting the Most Out of Your API Security Assessment

Tips for what you can do in advance of an API Security Assessment to help us avoid delays and ensure the process runs smoothly and benefits everyone.

Read about this article
Podcasts December 06 2024

Security Noise - Episode 7.7

Amazing Stories in InfoSec

Read about this article
Blog May 14 2024

Introducing Meta-Detector

In this blog post, I’m going to discuss a new Open-Source Intelligence (OSINT) tool I created to assist with collecting information about target organizations…

Read about this article
Podcasts March 29 2024

Security Noise - Episode 6.17

A Royal OSINT

Read about this article
Podcasts February 23 2024

Security Noise - Episode 6.15

OSINT: Digital Detective or Cyber Stalking?

Read about this article
Blog September 21 2023

Basic Authentication Versus CSRF

I was recently involved in an engagement where access was controlled by Basic Authentication. One (1) of the findings I discovered was a Cross-Site Request…

Read about this article
Podcasts September 15 2023

Security Noise - Episode 6.8

Geoff Walton and Skyler Tuter discuss the past, present, and future of AppSec with security experts Joe Sullivan, Philip DuBois, and Scott White, exploring…

Read about this article
Blog June 27 2023

Introducing CoWitness: Enhancing Web Application Testing With External Service Interaction

CoWitness improves web application testing by capturing complete DNS and HTTP responses, revealing false positives and hidden vulnerabilities, and helping…

Read about this article
Podcasts November 07 2022

TrustedSec Security Podcast - Episode 5.13

Episode - 5.13 - A Dastardly End for Windows 7

Read about this article

Empower your business through better security design.

Talk directly with our experienced advisory consultants to learn how we can help.