Name
dawid-esterhuizen
desterhuizen—cloud security governance at organisation scale
Synopsis
desterhuizen [--cloud-governance] [--aws] [--appsec] [--exploit-dev] [--red-team] [--tooling] desterhuizen --based netherlands --tz CET --since 2006
Description
I set the cloud and security governance that MongoDB's Professional Services organisation runs on. I also hold OSCE³, OSCP and OSDA — so I know how the controls I write fail under attack.
Most security leaders inherit their threat model. I built mine: two years pentesting MongoDB's own internal tools white-box and black-box, and two years on the Synack Red Team. I write and release my own tooling — exploit development and ROP scripts, payload generation, and a provisioning framework for reproducible penetration testing workstations.
Before this: twenty years building the systems I now secure. Game backends at Arooga and SEGA Europe, and primary AWS administrator on every estate I have run since 2013.
I also hold an MBA. Mostly it is useful for one thing — explaining to the people who control budgets why a finding matters, in their language rather than mine.
Options
--cloud-policy-framework
Defines how every consulting engineer operates in cloud environments, with automated tooling that enforces it. Corporate Cloud Security is rolling parts of it out globally.
--portal
Built and own the platform used daily for onboarding, training management and spend monitoring. It replaced a manual process.
--tradecraft
Rebuilt the lab curriculum around real production deployments, and run architecture and cloud design reviews for consulting engineers and partners worldwide.
--security-posture
Work alongside InfoSec, Cloud Security and the Red Team, and on the security design of internal tools with the Search, Vector Search and AI teams.
Repositories
~/w1ld0s
Bash · AGPL-3.0Idempotent bash provisioning for a reproducible Ubuntu 26.04 penetration testing workstation. Seventeen modules, per-tool Python virtualenvs, and declarative manifests acting as lock files — built to avoid the dependency conflicts that come with pre-packaged offensive distributions.
~/w1ld0s-tools
Bash · AGPL-3.0Operator command layer on top of w1ld0s — recon, access, infrastructure and Active Directory workflows, per-engagement state, and offline cheatsheets. Deliberately separate: the workstation changes rarely, the operator tooling changes weekly.
~/exploit-tools
PythonExploit development tooling, focused on Return Oriented Programming.
~/exploit-development-scripts
PythonScripts used when reverse engineering and doing exploit development.
~/payloader
PythonPayload generation from a simple CLI, for faster access to custom payloads.
History
-
2026 —
Distinguished Consulting Engineer
MongoDB
Technical direction for Professional Services cloud infrastructure, security posture and enablement across the organisation.
-
2024 – 26
Principal Service Delivery Enablement Engineer
MongoDB
Took ownership of cloud infrastructure for the whole Professional Services department — creating, enforcing and monitoring cloud policy, and building the tooling behind it.
-
2023 – 25
Red Team Member
Synack Red Team
Targeted penetration tests within Synack's engagement scopes, using standard tooling and custom tools I wrote. Discretionary time; not primary employment.
-
2022 – 24
Information Security Engineer II
MongoDB
White-box and black-box pentests of internally developed tools and products. Started a monthly offensive hackathon and built most of the challenges; carried L1 incidents on the on-call rota.
-
2014 – 18
Senior Server Engineer
SEGA Europe
Backend for Kingdom Conquest 3, primary AWS administrator for the studio estate, and a high-throughput analytics pipeline for future titles.
-
2013 – 14
Director of Server Technology
Arooga
Owned server technology across IaaS estates — including the auto-scaling behind Robocraft, built to scale down without users noticing.
Certifications
| Code | Certification | Issuer | Earned |
|---|---|---|---|
| OSCE³ | Offensive Security Certified Expert 3 | OffSec | Apr 2026 |
| OSED | Exploit Developer | OffSec | Apr 2026 |
| OSEP | Experienced Penetration Tester | OffSec | May 2025 |
| OSDA | Defense Analyst | OffSec | Nov 2024 |
| OSWP | Wireless Professional | OffSec | Apr 2024 |
| OSWE | Web Expert | OffSec | Feb 2024 |
| OSCP | Certified Professional | OffSec | Apr 2023 |
| CEH Master | Certified Ethical Hacker (Master) | EC-Council | to Sep 2027 |
External publications
Experiments
Author
Opinions here are my own, not my employer's.