D. Esterhuizen TLP:CLEAR
Offensive Security REF: ENG-2026-001 REGION: EMEA / GLOBAL STATUS: ACCEPTING ENGAGEMENTS

I find the attack paths in your crown jewels before someone else does.

Independent offensive security consultant. Twenty years of engineering, eight of them deep inside MongoDB. I break database deployments, cloud estates, and AI systems under controlled conditions — then hand you the fix.

// hover the redactions — disclosure is always controlled

Credentials
OSCE³
OSEP
OSWE
OSED
OSCP
OSDA
OSWP
CEH Master

Capabilities

Six ways your environment gets tested.

FORMAT: FINDING-STYLE

SVC-01Specialty

MongoDB Security Assessment

Authentication, authorization, encryption, network exposure, and operational hardening of MongoDB and Atlas deployments — reviewed by someone who spent eight years inside the vendor. Misconfigurations attackers actually exploit, not checklist noise.

AtlasSelf-managedSharded clustersQueryable Encryption
SVC-02Regulated

Red Team Operations

Threat-intelligence-led adversary simulation for regulated environments. Built for TIBER-EU, DORA, and CBEST contexts — scoped, evidenced, and reported to the standard your regulator expects.

TIBER-EUDORACBESTPurple team
SVC-03Cloud

Cloud Security Architecture

Offensive review of AWS, Azure, and GCP estates: identity boundaries, privilege escalation paths, data-exfiltration routes, and the cross-account trust relationships nobody documented.

AWSAzureGCPIAM attack paths
SVC-04Emerging

AI / LLM Security

Adversarial testing of LLM-backed applications: prompt injection, data leakage, tool-abuse chains, and the trust boundaries between your model, your data, and your users.

Prompt injectionRAG pipelinesAgent tooling
SVC-05Whitebox

Source Code Review & Exploitation

Manual, white-box review of your application source: logic flaws, authentication bypasses, injection, unsafe deserialization, and the insecure data flows scanners walk straight past. Every finding proven with a working exploit, not a static-analysis maybe.

White-boxLogic flawsAuth bypassInjectionDeserialization
SVC-06Binary

Binary Exploitation

Reverse engineering and exploitation of compiled applications and native services: memory-corruption bugs, unsafe parsing, and the trust boundaries inside the binaries your security depends on. From root cause to a reliable proof-of-concept.

Reverse engineeringMemory corruptionFuzzingROP / mitigations

Method

Engagements run like operations, not audits.

PHASE 01

Scope & rules of engagement

Targets, exclusions, escalation contacts, and legal authorization agreed in writing before a single packet moves.

PHASE 02

Reconnaissance & threat modeling

Your environment mapped the way an adversary would map it — externally first, assumptions last.

PHASE 03

Controlled exploitation

Attack paths executed under agreed constraints, with full evidence capture and no production surprises.

PHASE 04

Reporting & remediation

Findings ranked by real exploitability, each with a reproduction path and a concrete fix. Debrief with your engineers, not just your auditors.

PHASE 05

Retest

Fixes verified, residual risk stated plainly, report closed out.

Track record

Background that doesn't need embellishing.

20+
Years in software & security engineering
8
Years at MongoDB Inc., Principal level
OSCE³
8 offensive security certifications incl. OSEP, OSWE & OSED
SRT
Synack Red Team researcher
MDBW
MongoDB World speaker — "Hack the MongoDB Planet!!"
EMEA
Netherlands-based, available globally

Engagement models

Three ways to work together.

Fixed-scope assessment

Defined targets, defined timeline, defined deliverable. Best for MongoDB reviews, cloud architecture assessments, and AI/LLM testing.

TYPICAL: 1–3 WEEKS

Red team operation

Intelligence-led, objective-based campaigns for regulated entities. Solo or embedded in your provider's team under TIBER-EU / CBEST frameworks.

TYPICAL: 4–12 WEEKS

Retained advisory

Ongoing offensive security counsel: architecture reviews, threat modeling, secure design input, and on-call expertise for your engineering teams.

TYPICAL: MONTHLY RETAINER

Writing / Research

Notes from the field.

ARCHIVE: 4 ENTRIES

Contact

Scope a controlled breach.

BASE  Netherlands · CET
RANGE  Remote-first · on-site across EMEA & global
PGP  Key available on request
Start the conversation