Skip to Main Content
All Trimarc services are now delivered through TrustedSec! Learn more

Luke Bremer

Senior Security Consultant II

EXPERIENCE
Luke Bremer has 12+ years of Security and IT experience and has worked with and written applications in .NET and .NET Core. Luke specializes in web application development and web application penetration testing to demonstrate basic and advanced tactics that help identify security issues in web applications, web APIs, and connected web services.

EDUCATION & CERTIFICATIONS

  • Bachelor of Science, Computer Science, Davenport University
  • OSWA
  • SEC+

INDUSTRY CONTRIBUTIONS
Luke has set up static and dynamic code scanners and written secure coding documentation and remediation guides, published several blogs on various security topics, and reported several zero-days in open source software.

PASSION FOR SECURITY
Luke has always had a passion for exploring and securing technology for himself and others. He is part of CTF and bug bounty programs, including TryHackMe, Hack The Box, HackerOne, and has been in the Burp Suite Academy top 50.

Featured Blogs And Resources

Discover the blogs, analysis, webinars, and podcasts by this team member.

Blog November 28 2023

What is Hackvertor (and why should I care)?

What’s Hackvertor and why should I care?Years ago, Gareth Heyes created a Burp Suite (Burp) extension called Hackvertor. It’s an extension with a lot of…

Read about this article
Blog August 31 2023

Crafting Emails with HTML Injection

Crafting emails with HTML injection vulnerabilities allows attackers to alter the email body, potentially revealing sensitive information or executing…

Read about this article
Blog May 23 2023

JavaScript Essentials for Beginning Pentesters

Learn how to format, search, and debug JavaScript files, bypass client-side restrictions, and use Burp Suite to alter script responses and improve your web…

Read about this article
Blog May 02 2023

Cross Site Smallish Scripting (XSSS)

Learn how to exploit XSS vulnerabilities in web applications, including techniques for pulling scripts from external sources, using input encoding and…

Read about this article
Blog October 27 2022

How to Get the Most Out of Your Pentest

TL;DR Define the goal of an assessment.Take time to choose the right assessment type.The more detail you give about an asset, the better quality your report…

Read about this article
Webinars April 15 2026

You Had Us at the First Alert: A Guide to Finding Frequently Missed Detections

Join us for this webinar to get a clearer picture of where your detection coverage has blind spots and a practical roadmap for closing them before a real…

Read about this article
Events TrustedSec HQ | March 31 2026

ISC2 Cleveland Chapter Member Meeting - March 2026

ISC2 Cleveland Chapter March MeetupCome join us for our meetup! The ISC2 Cleveland Chapter is hosting an exciting in-person event for all cybersecurity…

Read about this article
Blog March 26 2026

Policy as Code: Stop Writing Policies and Start Compiling Them

The Problem Nobody Wants to Talk AboutLet me paint a picture most security leaders will recognize.You have 30+ policies living as Word documents on SharePoint.…

Read about this article
Podcasts March 24 2026

Security Noise - AI is Exploring The Deep Blue CVEs

On this episode of Security Noise, we explore the cutting-edge use of AI in vulnerability research, exploit development, and cybersecurity defense with guests…

Read about this article
Blog March 24 2026

Building a Detection Foundation: Part 4 - Sysmon

Filling the Gaps Native Logging Can'tAt this point in our series, we have Windows Security events capturing logon sessions and process creation, and…

Read about this article

Empower your business through better security design.

Talk directly with our experienced advisory consultants to learn how we can help.