Skip to content

Justin White

Security tinkerer, maker, home-lab operator

justin@jlwhite.ca ·GitHub ·LinkedIn ·TryHackMe ·Credly

Summary

I lead cybersecurity for a large, privately held multinational, accountable for the global program end to end: architecture, GRC, and operations. I came up through networking and grew into standing up the function, so my bias is toward security an always-on operational business can actually live with. I stay hands-on, too: a home lab as a live testbed, and security writeups spanning cloud, web, and AI/LLM security.

What I lead

A function this size is never "finished": some of it I've built and run for years, some is mid-transformation, some is next. What stays constant is owning the whole arc, architecture through operations, and the team.

Capabilities and scope only. No tooling, architecture, incidents, or numbers tied to any employer. The detail that sits behind an NDA stays there. How I think about the work in practice is in the field notes.

Technologies

The technologies listed here are from self-directed work pursued independently (in a personal home lab, in solo open-source projects, through certification study, and in authorized security practice) for my own learning and advancement. They are NOT a representation of any employer's systems, tools, vendors, architecture, or environment, and not technologies I deploy, support, or manage in any professional capacity.

I bring the ideas, infrastructure, and security. My "phone a friend" brings the code.

Personal projects

Everything below comes out of four solo projects:

  • HouseGRC: a GRC platform. Reflex (Python full-stack), SQLAlchemy 2.0, SQLCipher-encrypted SQLite (optional Postgres), Alembic, a FastAPI sub-app, APScheduler, and a REST API.
  • DeepReview / superdeepreview: a passive-OSINT engine, with an opt-in, authorized-use-only active edition.
  • GYST: a self-hosted household PWA on Reflex + Granian.
  • jlwhite.ca: this site, on Astro and Cloudflare Pages.
Languages and frameworks

What I build those with.

Python · Reflex · Granian · FastAPI · Pydantic · SQLAlchemy 2.0 · asyncpg · Alembic · APScheduler · arq (Redis) · React · Vite · TypeScript · Tailwind · TanStack Query · Recharts · Astro · sharp · service workers · VAPID push

Cloud and identity

Built into my own apps and certification study, not an operated environment.

SAML 2.0 · OIDC/OAuth SSO · SCIM 2.0 · group RBAC · MFA (TOTP) · WebAuthn/passkeys · AWS (boto3) · GitHub connector · Okta connector · S3 / SFTP / WebDAV · Cloudflare Pages · DNS/DNSSEC · Azure/Entra ID certified

AI / LLM engineering

Multi-provider LLM work, from review engines to agentic assistants.

Anthropic · OpenAI · Gemini · Cohere · Mistral · DeepSeek · multi-pass review engine · adversarial LLM verification · agentic tool-use (40+ tools) · vision LLMs · OWL-ViT (local) · barcode scanning · Open Food Facts · Web Speech voice · prompt-injection guardrails · n8n ops agent

Application and offensive security

Authorized practice on TryHackMe and CTFs, plus the OSINT tooling in DeepReview.

Azure/Entra ID privesc · Microsoft Graph · Temporary Access Pass · SSRF (PDF renderers) · stored XSS · injection · CVE analysis · prompt-injection chaining · DNS/DNSSEC · nmap · gobuster · hashcat · Kali · AzureHound · Azure CLI · 40+ OSINT collectors · subfinder · httpx · nuclei · Tor · SearXNG · Docker sandbox

Infrastructure and home lab

A four-node Proxmox cluster on my own hardware.

Proxmox · Docker · Docker Compose · LXC · Caddy · Cloudflare edge · Linux · Plex · Audiobookshelf · n8n · Ansible · restic · Wazuh · Zabbix · Graylog

Data and cryptography

Data stores I run, and the crypto and appsec primitives I implemented across the apps.

Postgres · Redis · SQLite · SQLCipher · AES-256-GCM · Fernet · PBKDF2 · argon2 · TOTP · WebAuthn · HMAC · hash-chained audit trails · HMAC-signed webhooks · SSRF allow-lists · prompt-injection fencing · security-invariant tests

Networking

Home network, plus routing and switching depth backed by Cisco and Juniper certs.

pfSense (CARP HA) · dual-WAN failover · fibre + Starlink · VLAN segmentation · Pi-hole DNS · DNSSEC · UniFi · Cisco lab · routing & switching · trunking · spanning-tree · firewalls · VPNs

Electronics and making

The hardware bench.

Raspberry Pi 5 · Hailo-8 · Pi Pico W · ESP32 · MicroPython · MQTT · PlutoSDR · LibreSDR · pH/EC sensors · FDM 3D printing

Selected writeups

Hands-on practice

  • TryHackMe: offensive-security practice rooms. View profile →
  • Home lab: a four-node Proxmox cluster running an active/passive pfSense HA firewall, redundant Pi-hole DNS with DNSSEC, Docker/LXC services, and monitoring (Wazuh, Zabbix) as a live environment to test against.
  • Open source: public work on GitHub, including this site.

Credentials

Certifications

All certifications, verified on Credly →

Experience

  • Director, Cybersecurity, Large privately held multinational Oct 2025 – present
    Accountable for the global cybersecurity posture across more than a dozen countries and tens of thousands of employees: security architecture, GRC, and security operations.
  • Senior Manager, IT Security, Large privately held multinational Jan 2023 – Oct 2025
    Built and operationalized the enterprise cybersecurity function spanning security architecture, GRC, and security operations.
  • Network & architecture roles, Large privately held multinational Feb 2018 – Jan 2023
    Senior IT Architect; Team Lead, Network Services; and Senior Network Analyst. Ran the enterprise network across several countries, built a disaster-recovery datacenter, handled secure network cutover for acquired companies, and replaced legacy wireless that couldn’t be secured.
  • Infrastructure Analyst → Senior Network Analyst, Diversified industrial conglomerate ~2008 – Feb 2018
    Led core and datacenter network redesign and segmentation, and served as network lead on security projects and major incident response.
  • Service desk & field services, Various contracts 2003 – 2008
    Where it started: a string of contracts on the service desk and out in field services, the unglamorous trade of keeping hardware and humans running. A lot of tickets, a lot of windshield time, and the foundation everything since was built on.