Justin White
Security tinkerer, maker, home-lab operator
Summary
I lead cybersecurity for a large, privately held multinational, accountable for the global program end to end: architecture, GRC, and operations. I came up through networking and grew into standing up the function, so my bias is toward security an always-on operational business can actually live with. I stay hands-on, too: a home lab as a live testbed, and security writeups spanning cloud, web, and AI/LLM security.
What I lead
A function this size is never "finished": some of it I've built and run for years, some is mid-transformation, some is next. What stays constant is owning the whole arc, architecture through operations, and the team.
Capabilities and scope only. No tooling, architecture, incidents, or numbers tied to any employer. The detail that sits behind an NDA stays there. How I think about the work in practice is in the field notes.
Technologies
The technologies listed here are from self-directed work pursued independently (in a personal home lab, in solo open-source projects, through certification study, and in authorized security practice) for my own learning and advancement. They are NOT a representation of any employer's systems, tools, vendors, architecture, or environment, and not technologies I deploy, support, or manage in any professional capacity.
I bring the ideas, infrastructure, and security. My "phone a friend" brings the code.
- Personal projects
-
Everything below comes out of four solo projects:
- HouseGRC: a GRC platform. Reflex (Python full-stack), SQLAlchemy 2.0, SQLCipher-encrypted SQLite (optional Postgres), Alembic, a FastAPI sub-app, APScheduler, and a REST API.
- DeepReview / superdeepreview: a passive-OSINT engine, with an opt-in, authorized-use-only active edition.
- GYST: a self-hosted household PWA on Reflex + Granian.
- jlwhite.ca: this site, on Astro and Cloudflare Pages.
- Languages and frameworks
-
What I build those with.
Python · Reflex · Granian · FastAPI · Pydantic · SQLAlchemy 2.0 · asyncpg · Alembic · APScheduler · arq (Redis) · React · Vite · TypeScript · Tailwind · TanStack Query · Recharts · Astro · sharp · service workers · VAPID push
- Cloud and identity
-
Built into my own apps and certification study, not an operated environment.
SAML 2.0 · OIDC/OAuth SSO · SCIM 2.0 · group RBAC · MFA (TOTP) · WebAuthn/passkeys · AWS (boto3) · GitHub connector · Okta connector · S3 / SFTP / WebDAV · Cloudflare Pages · DNS/DNSSEC · Azure/Entra ID certified
- AI / LLM engineering
-
Multi-provider LLM work, from review engines to agentic assistants.
Anthropic · OpenAI · Gemini · Cohere · Mistral · DeepSeek · multi-pass review engine · adversarial LLM verification · agentic tool-use (40+ tools) · vision LLMs · OWL-ViT (local) · barcode scanning · Open Food Facts · Web Speech voice · prompt-injection guardrails · n8n ops agent
- Application and offensive security
-
Authorized practice on TryHackMe and CTFs, plus the OSINT tooling in DeepReview.
Azure/Entra ID privesc · Microsoft Graph · Temporary Access Pass · SSRF (PDF renderers) · stored XSS · injection · CVE analysis · prompt-injection chaining · DNS/DNSSEC · nmap · gobuster · hashcat · Kali · AzureHound · Azure CLI · 40+ OSINT collectors · subfinder · httpx · nuclei · Tor · SearXNG · Docker sandbox
- Infrastructure and home lab
-
A four-node Proxmox cluster on my own hardware.
Proxmox · Docker · Docker Compose · LXC · Caddy · Cloudflare edge · Linux · Plex · Audiobookshelf · n8n · Ansible · restic · Wazuh · Zabbix · Graylog
- Data and cryptography
-
Data stores I run, and the crypto and appsec primitives I implemented across the apps.
Postgres · Redis · SQLite · SQLCipher · AES-256-GCM · Fernet · PBKDF2 · argon2 · TOTP · WebAuthn · HMAC · hash-chained audit trails · HMAC-signed webhooks · SSRF allow-lists · prompt-injection fencing · security-invariant tests
- Networking
-
Home network, plus routing and switching depth backed by Cisco and Juniper certs.
pfSense (CARP HA) · dual-WAN failover · fibre + Starlink · VLAN segmentation · Pi-hole DNS · DNSSEC · UniFi · Cisco lab · routing & switching · trunking · spanning-tree · firewalls · VPNs
- Electronics and making
-
The hardware bench.
Raspberry Pi 5 · Hailo-8 · Pi Pico W · ESP32 · MicroPython · MQTT · PlutoSDR · LibreSDR · pH/EC sensors · FDM 3D printing
Selected writeups
- Azure / Entra ID privilege escalation: managed identity → Microsoft Graph token → Temporary Access Pass → account takeover
- Web SSRF through a server-side PDF renderer
- AI-pentest room: stored XSS against a reviewer bot, chained with LLM prompt injection
- AI security: scoping an LLM ops-agent for a Proxmox cluster
- Home lab: HA pfSense on Proxmox with dual-WAN failover
- Home-lab DNS / DNSSEC troubleshooting
Hands-on practice
- TryHackMe: offensive-security practice rooms. View profile →
- Home lab: a four-node Proxmox cluster running an active/passive pfSense HA firewall, redundant Pi-hole DNS with DNSSEC, Docker/LXC services, and monitoring (Wazuh, Zabbix) as a live environment to test against.
- Open source: public work on GitHub, including this site.
Credentials
Certifications
All certifications, verified on Credly →
Experience
- Director, Cybersecurity, Large privately held multinational Oct 2025 – present Accountable for the global cybersecurity posture across more than a dozen countries and tens of thousands of employees: security architecture, GRC, and security operations.
- Senior Manager, IT Security, Large privately held multinational Jan 2023 – Oct 2025 Built and operationalized the enterprise cybersecurity function spanning security architecture, GRC, and security operations.
- Network & architecture roles, Large privately held multinational Feb 2018 – Jan 2023 Senior IT Architect; Team Lead, Network Services; and Senior Network Analyst. Ran the enterprise network across several countries, built a disaster-recovery datacenter, handled secure network cutover for acquired companies, and replaced legacy wireless that couldn’t be secured.
- Infrastructure Analyst → Senior Network Analyst, Diversified industrial conglomerate ~2008 – Feb 2018 Led core and datacenter network redesign and segmentation, and served as network lead on security projects and major incident response.
- Service desk & field services, Various contracts 2003 – 2008 Where it started: a string of contracts on the service desk and out in field services, the unglamorous trade of keeping hardware and humans running. A lot of tickets, a lot of windshield time, and the foundation everything since was built on.