Brad Geesaman

bgeesaman in/bradgeesaman @bradgeesaman Fairfax, VA

Summary

Motivated cloud-native Information Security Professional with expertise in a wide range of cloud platform and Kubernetes security technologies and a track record of producing extraordinary results. Looking for opportunities to make the secure path the easier path for your clients and the community.

Experience

2022-present

Staff Security Engineer, Ghost Security

2021-2022

Director of Cloud Security, Aqua Security

2019-2021

Co-founder, Chief Architect, Darkbit.io

2018-2019

Professional Services Consultant (Contractor/TVC), Google Cloud (PSO)

2018-2019

Independent Security Consultant, Bradley Geesaman Consulting

2015-2017

Senior Manager, Symantec Corporation

2014-2015

CTO, Blackfin Security Group - Acquired by Symantec Corporation

2012-2014

Chief Architect, MAD Security

2008-2012

Security/Sales Engineer, Check Point Software Technologies

2006-2008

Manager, Assessment Services, Securicon

2004-2006

Principal Security Engineer, Symantec Corporation

2003-2004

Security Engineer/Senior Security Engineer, Symantec Corporation

2002-2003

Systems Engineer, PEC Solutions

Speaking

KubeCon EU 2023 Malicious Compliance: Reflections on Trusting Container Scanners

KubeCon NA 2021 Exploiting a Slightly Peculiar Volume Configuration with SIG-Honk

KubeCon NA 2021 Kubernetes Exposed! Seven of Nine Hidden Secrets That Will Give You Pause

KubeCon NA 2020 Keynote Panel: Hacking and Hardening in the Cloud Native Garden

CSA Boston Oct 2020 Kubernetes Attacks: What Your Cluster Is Trying To Tell You

RSA 2020/KubeCon EU 2020 Advanced Persistence Threats: The Future of Kubernetes Attacks

KubeCon NA 2019 Attacking and Defending Kubernetes Clusters: A Guided Tour

BlackHat USA 2018 Detecting Malicious Cloud Account Behavior

KubeCon NA 2017 Hacking and Hardening Kubernetes Clusters By Example

Vuln Research

2020 CVE-2020-15157 “ContainerDrip” Write-up and Google 2020 VRP Prize Winner

Falco Default Rule Bypass

Container Registry Search Order/Registry Name Squatting

2019 CVE-2019-11253 Kubernetes DoS Writeup

Certifications

2020-present Google Cloud Certified Fellow

2020 Certified Kubernetes Security Specialist Exam Developer

2019-present Google Cloud Certified Professional Cloud Architect

2007-2016 Certified Information System Security Professional (CISSP), ISC2

2004-2006 RedHat Enterprise Linux Certified Engineer (RHCE), RHEL 3.0

Education

1998-2002 BBA, Computer Information Systems, James Madison University, VA, USA.

Interests

Hockey, Formula 1™, Cloud/Kubernetes Vulnerability Hunting, Mexican food, and collecting e-books