Skip to content

Offensive Security Consultant · Red Team Operator

Nathan B. Herron

I run red team operations and penetration tests that emulate real-world threat actors, then turn the results into remediation guidance leadership can act on.

  • RTAC
  • NSA Red Team Operator
  • GIAC GPEN

01 / About

Background

Cybersecurity consultant with six years of professional experience conducting red team operations that emulate real-world threat actors. I lead internal, external, and web application penetration tests, build the infrastructure and tooling that supports them, and translate the results into remediation guidance for audiences ranging from technical staff to executive leadership.

Summerville, South Carolina

02 / Resume

Experience & credentials

Roles, education, certifications, and published research.

Experience

Senior Consultant · Palo Alto Networks Unit 42

November 2024 – Present

  • Served as Case Lead on client engagements, directing the activities of consultants and supporting staff to ensure assessment objectives were met within defined scope, rules of engagement, and delivery timelines.
  • Delivered internal, external, and web application penetration tests tailored to each organization's unique threat landscape and risk tolerance.
  • Presented tactics, techniques, and procedures (TTPs) to offensive security practitioners at a recurring weekly internal forum, fostering knowledge sharing and continuous capability development across the consulting team.
  • Developed custom scripts, tools, and automations in Python, Bash, and Go to streamline internal engagement processes and enhance offensive capability.
  • Authored assessment reports detailing testing methodologies, findings, and prioritized remediation recommendations for audiences ranging from technical staff to C-suite leadership.

Red Team Operator · NAVWAR Red Team

June 2020 – November 2024

  • Led red team operations emulating adversary tradecraft against mission-critical DoD and DHA networks, conducting both external and internal access operations.
  • Built and maintained red team infrastructure, including phishing domain acquisition, redirector deployment, and standing up and sustaining attack platforms.
  • Conducted both onsite and remote adversarial operations to evaluate the security posture of client networks and test detection capabilities of affiliated Cyber Security Service Providers (CSSPs).
  • Maintained long-term persistence on target networks, exercising defender response and driving measurable improvement in system security posture.
  • Authored operation orders, rules of engagement, assessment reports, and technical briefings; presented findings and remediation guidance to system stakeholders.

Red Team Intern · NAVWAR Red Team

June 2018 – June 2020

  • Executed red team operations and delivered technical briefings.
  • Developed a small-scale virtual cyber range for the testing of adversarial TTPs.

Education

Master of Science in Computer and Information Sciences

May 2020

University of South Alabama

National Center of Academic Excellence in Information Assurance/Cyber Defense

Bachelor of Science in Computer Science

May 2018

University of South Alabama

Mathematics minor

Skills

  • Conduct penetration testing across Windows, Linux, and Active Directory environments using open-source, commercial, and custom tooling.
  • Operate industry-standard C2 frameworks including Cobalt Strike and Sliver.
  • Build and maintain red team infrastructure, including redirector deployment and attack platform development.
  • Craft and modify custom exploits and payloads independent of consumer frameworks.
  • Evade blue team signatures and Indicators of Compromise (IOCs) through advanced adversarial tradecraft.
  • Lead phishing campaigns from payload development to distribution.
  • Develop offensive tooling and automation in Python, Bash, and Go.
  • Apply CVSS, MITRE ATT&CK, and NIST standards to reporting, disclosure, and risk assessment.
  • Communicate technical findings and risks to audiences ranging from technical staff to executive leadership, both written and verbal.

Professional Development

Certifications, Training, & Presentations

Summer 2020 – Present

  • K>FiveFour, Red Team Apprentice Certified (RTAC) (2021).
  • NSA Certified Red Team Operator (2020 – Present).
  • SANS Institute, GIAC Penetration Tester (GPEN) (2020).
  • Presented TTPs to the NAVWAR Penetration Testing Community of Interest (2020 – 2024).

Research Groups & Continuing Education, University of South Alabama

Fall 2014 – 2020

  • Weekly DayZero meetings to study ethical hacking skills and techniques.
  • Weekly Software Protection and Exploitation Research Group (SPERG) meetings.
  • Weekly Digital Forensics research meetings covering forensic methodology.
  • Monthly lectures for Centers of Forensics, Information Technology & Security (CFITS).
  • Participated in Capture the Flag events including HackTheBox, VulnHub, CSAW, Cyberlympics, and Panoply.

DayZero Organization, University of South Alabama — Treasurer

Spring 2016 – 2020

  • Conducted weekly presentations on information security concepts and penetration testing tools to students and faculty.
  • Managed organization funds and secured SGA appropriations.

Publications

McDonald, J., Herron, N., Glisson, W., & Benton, R. (2021). Machine Learning-Based Android Malware Detection Using Manifest Permissions. Hawaii International Conference on System Sciences (HICSS-54)

Awards & Honors

  • NIWC LANT 5.9 Competency On The Spot! Award (2020, 2021, 2022, 2023, 2024).
  • CyberCorps: Scholarship for Service (SFS) (August 2017 – May 2020).
  • Commendation by the Governor of Alabama (December 2017).
  • Fifth place in the National Cyber Defense Competition (April 2017).
  • Winner of the Southeastern Conference Cyber Defense Competition (March 2017).
  • Dean's List (Fall 2012 – Spring 2016).
  • Bay Area Freshman Scholarship (August 2011 – August 2013).

03 / Portfolio

Selected work

Case studies in progress

Selected engagements, tooling, and research will be published here.

04 / Contact

Get in touch