Thato Aphane
Senior Offensive Security & Cloud Security Engineer
I break systems before attackers do — and build them stronger than before.
// Core Expertise
| Domain | Skills |
|---|---|
| Offensive Security | Red Teaming, Exploit Dev, C2, Purple Team Ops, OSINT, Social Engineering |
| Cloud Security | Azure Security Architecture, AWS Hardening, GCP IAM, CSPM, Zero-Trust |
| DevSecOps | CI/CD Security (GitHub, GitLab, Jenkins), IaC Review, Container Security |
| Microsoft Security | Entra ID, Intune, M365 E5, Defender XDR, Purview DLP, Conditional Access |
| Blue-Team Engineering | SIEM (Sentinel, Splunk), EDR, Threat Hunting, DFIR, Incident Response |
| Governance & Compliance | ISO 27001, PCI DSS, POPIA, NIST CSF, CIS Benchmarks, SOC 2 mappings |
| Secure Engineering | API security, microservices security, secure SDLC, threat modeling |
// Professional Experience
Senior Infrastructure and Security Engineer
Netsurit — November 2023 – Present
Design and implement secure network and cloud architectures, integrate security into engineering workflows, and lead incident response and compliance activities.
- Design and implement secure network architectures (firewalls, IDS/IPS, micro-segmentation) and SIEM solutions to strengthen security posture.
- Integrate automated security testing into CI/CD (Jenkins, GitLab CI, GitHub Actions) including SAST, DAST and dependency scanning to catch issues early.
- Lead incident response, forensic analysis, and remediation while minimising business impact.
- Manage IAM systems and conditional access policies to enforce least-privilege and strong authentication.
- Ensure and audit compliance with POPIA, PCI DSS and ISO 27001; develop policies and run internal audits.
- Evaluate and manage security vendor relationships and define key security metrics to drive improvements.
Technologies:
Azure, AWS, GCP, Office 365/Microsoft 365, Splunk, Nessus, Wireshark, Active Directory, Azure AD, Docker, Jenkins, GitLab CI, GitHub Actions, Python, Bash
Azure & Microsoft 365 highlights
- Azure Security Center / Microsoft Defender for Cloud: managed policies and multi-tenant compliance assessments.
- Azure Key Vault: secured certs, secrets and keys.
- NSGs, Azure Policy, Monitor & Log Analytics, Conditional Access: implemented governance, logging and risk-based access.
- Exchange Online Protection, DLP & M365 Compliance: configured protections and compliance reporting.
Senior Cloud Security Analyst / Pen Tester
Jinjer.co.za — May 2021 – October 2023 (Contract / Full-time)
Performed infrastructure and application penetration tests, developed testing tooling and methodology, and provided technical consultation to uplift client security.
- Executed network, web and mobile penetration tests, social engineering and physical security reviews.
- Developed custom exploits, scripts and automation to support continuous security assessments.
- Authored rules of engagement, security standards and automation for repeatable testing.
- Performed code reviews and worked with developers to validate and remediate vulnerabilities.
- Delivered workshops and training to share techniques and findings with technical and non-technical audiences.
Technologies:
Metasploit, Burp Suite, Nessus, Wireshark, Kali Linux, Python, Bash
IT Security Specialist
Johannesburg City Parks & Zoo — August 2017 – March 2023
Implemented and administered enterprise security solutions across on-prem and cloud, managed IAM, conducted pentests, and owned business continuity planning and compliance.
- Designed and administered identity platforms (Active Directory, Azure AD), group policy and related IAM tooling.
- Performed ethical hacking and managed EDR/anti-malware and SIEM tooling.
- Implemented security principles and controls including PKI, RADIUS, LDAP, SAML/OAuth, MFA, PAM and Zero Trust concepts.
- Managed compliance and security operations across virtualization, messaging, networking and data centre infrastructure.
Azure & Microsoft 365 highlights
- Defender for Cloud, Key Vault, NSGs, Azure Policy, Monitor & Log Analytics, Conditional Access.
- Exchange Online Protection, M365 Compliance Center, SharePoint/OneDrive sharing controls, Teams security and Power Platform governance.
IT Senior Analyst
Webhelp SA Outsourcing — March 2014 – May 2017
Day-to-day monitoring, investigation and response to cybersecurity alerts; automation of processes and vulnerability management across the estate.
- Operated anti-malware and vulnerability management tooling (Nessus, Qualys), and automated monitoring & alerts.
- Managed incident response, access reviews and security awareness initiatives across the business.
- Supported penetration testing, policy enforcement and security standards across projects and operations.
Systems Administrator
LDS Church Corporate Administration Offices — December 2008 – March 2012 (Contract)
Managed systems administration tasks including configuration, performance tuning, security management and ITIL-based operational processes.
- Worked on Windows Server, Cisco networking and VMware; supported incident/change/problem management and performance tuning.
- Assisted with network device configuration and developer workstation optimization for production workloads.
Key Metrics & Security Automation
Pipeline security integration and automation highlights across engagements.
- Integrated automated security tests at multiple stages of development (SAST, DAST, dependency scanning) to catch vulnerabilities earlier in the lifecycle.
- Reduced manual testing overhead and improved secure deployment cycles across client environments.
// Key Projects & Case Studies
Azure Zero-Trust Enterprise Rollout
Global Logistics Group — 12,000 Users
Deployed a full Zero-Trust identity model, blocking 80% of identity attacks and boosting MFA adoption to 98%.
Multi-Cloud Red Team Engagement
Fintech (Crypto Payments)
Discovered and demonstrated a critical privilege escalation chain from phishing to cloud persistence.
CI/CD Security Automation
GitHub & GitLab
Cut vulnerability remediation cycle by 60% via automated SAST, DAST, and IaC scanning.
Intune Deployment & Hardening
500 devices (Windows + macOS)
Rolled out ISO 27001-aligned endpoint baselines, ASR, and BitLocker/FileVault enforcement.
SOC & Cyber Defense Modernization
Sentinel + Defender XDR
Engineered MITRE ATT&CK–aligned detection rules and automated IR playbooks.
Secure Cloud Migration
Healthcare
Led HIPAA & POPIA-aligned migration with Zero-Trust segmentation and CMK encryption.
Web/App/API Pen Tests (20+)
.NET, Node, Python, React
Remediated critical findings like JWT manipulation, SSRF, and IDOR in multi-tenant apps.
Purple Team Exercise Program
Adversary Emulation
Developed and executed adversary emulation playbooks to validate and uplift SOC capabilities.
Ransomware Readiness Program
Enterprise Defense
Mapped attack paths, implemented immutable backup strategies, and tuned EDR for response.
AI-Assisted Threat Detection Lab
R&D Prototype
Prototyped an LLM-augmented SOC for automated intel parsing and adversarial prompt testing.
Payment Security Assurance
PCI DSS
Uplifted vulnerability management lifecycle and validated tokenization controls for compliance.
Secure Access & PAM Program
Privilege Management
Deployed JIT access, privilege segmentation, and session recording using Defender PIM.
// Credentials & Tools
Certifications
Current Certifications
- ✅ OSCP — Offensive Security Certified Professional
- ✅ CISSP — Certified Information Systems Security Professional
- ✅ AZ-500 — Azure Security Engineer Associate
- ✅ Certified Ethical Hacker (CEH)
- ✅ CompTIA Security+, Network+, A+, Linux+, Python+
Planned / Roadmap
- 🎯 CRTO I/II — Certified Red Team Operator
- 🎯 CCSP — Certified Cloud Security Professional
- 🎯 GIAC (GPEN, GXPN, GCIA)
Elite-Track Mastery
- 🚀 OSEP — Offensive Security Experienced Penetration Tester
- 🚀 OSWE — Offensive Security Web Expert
- 🚀 CRTE — Red Team Expert
Tools & Platforms
- Offensive: Burp Suite Pro, Cobalt Strike, Havoc, Metasploit, Nmap
- Defensive: Splunk, Sentinel, Defender, Nessus, Qualys, EDR/XDR
- Cloud: Azure, AWS, GCP
- Automation: Python, Bash, PowerShell, Terraform
// Get In Touch
I'm always open to discussing new projects, creative ideas, or opportunities to be part of an ambitious team.
Say Hello