Hi, I'm Kenny! Cybersecurity Professional & Software Developer.
š Miami/Fort Lauderdale Area | š§ kennyaranda46@gmail.com | š kennyaranda.com
š Download Resume (PDF)š About Me
Iām a cybersecurity professional and software developer with hands-on experience in penetration testing, mobile app security (iOS & Android), vulnerability assessments, and full-stack application development.
- š”ļø Skilled at identifying and mitigating security risks, developing custom exploits, and automating testing workflows.
- ā” Experienced in cloud security (AWS, Azure, GCP), CI/CD security testing, and building secure, scalable systems.
- š Active bug bounty hunter on HackerOne, passionate about offensive security and red team operations.
- š Certified in Burp Suite, eJPT, LPI Linux Essentials, and more.
š Education
University of North Florida ā Jacksonville, FL
B.S. in Computing and Information Sciences, Computer Science (ABET-accredited)
01/2020 - 05/2024
š Training & Certifications
- CyberWarfare - Web Red Team Analyst (Web-RTA) ā 07/2026
- Certified Agentic AI Pentester (C-AIPen) ā 06/2026
- CompTIA Security+ ā 02/2026
- eWPTX (Web Penetration Testing Extreme) by INE ā 01/2026
- eJPT (Junior Penetration Testing) by INE ā 01/2025
- Certified AI/ML Pentester (C-AI/MLPen) ā 10/2025
- Certified Network Security Practitioner (CNSP) ā 09/2025
- Certified AppSec Practitioner v2 (CAP) ā 09/2025
- CyberWarfare - Certified Red Team Analyst ā 08/2025
- CyberWarfare - Multi-Cloud Red Team Analyst (MCRTA) ā 08/2025
- LPI Linux Essentials Certification
- AWS Cloud Technical Essentials
- Cisco Intro to Cybersecurity
- OSCP Certification ā In progress
- Burp Suite Certified Practitioner ā In progress
š§āš» Experience
š Pentester @ SyscloudSec (07/2024ā08/2026)
- Attacked and compromised 50+ web, mobile, and API targets (REST/SOAP/GraphQL, iOS/Android), chaining vulnerabilities (IDOR, BOLA, authentication bypass) into full proof-of-concept exploits.
- Implemented secure authentication mechanisms (OAuth 2.0, JWT, SAML) and authorization controls following OWASP Top 10 best practices, reducing authentication-related vulnerabilities by 85%.
- Hunted external attack surfaces using OSINT tradecraft (Shodan, BBOT, Amass) and performed AI/ML API threat assessments, uncovering broken authentication and data exfiltration vectors.
- Conducted internal network penetration tests, access control reviews, and wireless security assessments (WPA2/WPA3).
- Ran adversarial social engineering campaigns (spear phishing, vishing) achieving 60% engagement rates, and engineered custom Python/PowerShell exploits to simulate threat actors.
- Built AI-powered security agents using Python and Claude AI (MCP integration) and automated security workflows in Python/n8n, cutting assessment cycles by 60%.
- Conducted PCI-DSS compliance assessments using Nessus Pro and Nmap, and produced 100+ pages of adversarial-focused reports with CVSS-scored findings.
š» Junior Software Developer @ Algorithmics (09/2021ā01/2024)
- Developed and maintained full-stack web applications (React, Node.js, MongoDB) for 1,000+ active users.
- Integrated PCI-DSS compliant third-party payment systems and APIs.
- Conducted quality assurance testing, code reviews, and pre-deployment secure code reviews, reducing production security bugs by 30%.
- Participated in Agile/Scrum workflows (sprint planning, daily stand-ups).
š» Security Intern @ SyscloudSec (02/2019ā05/2019)
- Executed initial web application and network penetration tests.
- Contributed to active threat monitoring and incident response, helping cut MTTR by 15%.
š§ Core Competencies
- Offensive Security & Pentesting: Web Application Pentesting, Mobile Security (iOS/Android), API Security (REST/SOAP/GraphQL), Network Pentesting, Wireless Security, Vulnerability Assessment, Exploit Development, Red Team Operations, Social Engineering
- Infrastructure & AD Exploitation: Active Directory Enumeration, Privilege Escalation, Lateral Movement, Credential Harvesting
- Tools & Frameworks: Burp Suite Pro, Metasploit, Nmap, Nessus Pro, Nuclei, OWASP ZAP, SQLmap, Wireshark, Aircrack-ng, MobSF, Frida, Objection, Hydra, Feroxbuster, Caido, Shodan, IntelligenceX
- OSINT & Reconnaissance: External Attack Surface Mapping, Subdomain Enumeration, DNS Analysis, Threat Intelligence Gathering, BBOT, Amass, Recon-ng, theHarvester
- Security Engineering & Automation: Python Exploit Development, Bash/PowerShell Scripting, Custom Tool Development, Docker, CI/CD Security, Cloud Security (AWS/Azure/GCP)
- Compliance & Reporting: PCI-DSS Assessment, Security Audit Methodologies (NIST, OWASP, PTES), Threat Modeling, Technical Report Writing, Risk Assessment & Remediation
š Featured Projects
- Scam Analyzer Agent ā AI-powered security agent built using OSINT, Claude Code, Burp Suite, Python, and GitHub Actions to analyze and detect phishing/scam infrastructure. (June 2026)
- OSINT Public Records Aggregator Bot ā Telegram bot leveraging Python, BeautifulSoup4, asyncio, Google Dorks, and API integrations to aggregate public records data. (March 2026)
- Hack The Box & TryHackMe Labs ā Hands-on penetration testing, vulnerability analysis, exploit development, and detailed writeups. (Ongoing)
𤳠Connect with me:
āļø Always learning, hacking, and building secure systems.