CV
Bijay Upreti — Offensive Security Consultant, Brisbane QLD, Australia
- Email: i@wingertries.net
- GitHub: @wingerbijay
- LinkedIn: bijayy-upreti
- TryHackMe: winger.bijay
Summary
Analytical, detail-driven offensive security consultant with 4+ years delivering internal and external network, Active Directory, web, and API penetration tests, red-team and adversary simulations, and phishing campaigns for enterprise clients. Comfortable chaining small findings into full attack paths, and able to explain both the risk and the fix to technical teams and executives alike.
Certifications
- OSCP — Offensive Security Certified Professional (OffSec · OS-ID: 57741730)
- PNPT — Practical Network Penetration Tester (TCM Security · ID: 95854169)
- CRTE — Certified Red Team Expert (Altered Security)
- eWPTX — Web Application Penetration Tester eXtreme (INE Security)
Experience
Offensive Security Consultant — Stickman Cyber Pty Ltd, Sydney
Jan 2022 – Present
- Ran internal and external network penetration tests for around 20 enterprise clients a year and delivered prioritised remediation for the exploitable findings.
- Assessed Active Directory across on-premises, hybrid, and cloud-only setups (Azure AD / Microsoft Entra ID), and traced privilege-escalation and lateral-movement paths through to domain and tenant compromise.
- Tested web applications and APIs for enterprise clients year-round against the OWASP Top 10 and provided developers with concrete remediation for each finding.
- Built custom Mythic C2 agents and prototyped a CI/CD pipeline to automate their builds and testing. Modified offensive tooling such as Impacket and NetExec to evade endpoint defenses, all tested in a self-built lab.
- Partnered with the SOC on purple-team exercises, matching offensive TTPs to their detections and closing blue-team coverage gaps.
- Kept several clients on a monthly vulnerability assessment cycle, tracked remediation over time, and sent prioritised reports.
- Led client debrief meetings and wrote the full penetration test reports, covering executive summaries, reproducible findings, risk ratings, and remediation, for both technical and executive audiences.
IT Support Analyst — Containers Exchange Services, Sydney
Sep 2021 – Jan 2022
- Provided first-line support for clients and staff through phone, email, and remote-control service.
- Leveraged a ticket-tracking system to prioritise, track, and document problem resolutions and notified end-users of issue status.
- Leveraged Power BI and Oracle Analytics to perform detailed searches for client support.
- Profiled desktops and laptops to make them user-ready, including Outlook, Teams, OneDrive, and SharePoint configuration.
Education
Melbourne Institute of Technology — BSc, Computer Networking Grade: 6.3 · Sydney · Graduated Jul 2020
Skills
Offensive Security: Internal/External Network Pentest · Active Directory (on-prem, hybrid, Entra ID) · Web & API Testing · Red-Team & Adversary Simulation · Phishing · Privilege Escalation · Lateral Movement · EDR Evasion · C2 Tradecraft · Purple Teaming
Tooling: Burp Suite · Nmap · Nessus · Metasploit · BloodHound · Impacket · NetExec · Responder · ffuf / gobuster · Mythic
Scripting: Bash · Python
Platforms: Azure / Microsoft Entra ID · Windows · Linux/Unix
Professional: Client Communication · Technical & Executive Reporting · Stakeholder Management · Team Collaboration · Adaptability
Interests
Home Lab — ProxMox, virtualisation, and Active Directory lab environments for hands-on research.
Security Community — Regular attendee at SecTalks, BSides, and CrikeyCon.