@NotMedici
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- United States App Store
Account-level information from X, not a live location or the device used for a specific post.
Back to Red Teaming. Risk Hunter. DEFCON Staff & CFP Board. MS in DF. Fmr Fire/EMS. Red and Blue. Builder. Morally Flexible. https://nitter.cf/t.co/zakkIXf6x2 @ bluesky
Joined February 2011
- Tweets9.8K
- Following1.7K
- Followers5.8K
- Likes57.2K
Tim McGuffin retweeted
I know it's early to be thinking about Internships for next summer but if you are interested in code security our internship applications for Summer 2027 are already open.
Read about what our Interns do
semgrep.dev/blog/2026/meet-t…
and then apply
semgrep.dev/about/careers/?a…
Tim McGuffin retweeted
I rarely share about my company, but it's such an amazing place to work
If you live and love Purview and AI Governance (and don't mind working with me...), we might have a role for you ;)
patriotconsulting.com/career…
32 hour weeks, great benefits, but most of all, amazing people :)
Tim McGuffin retweeted
Open for work!
My stint at Roblox has ended.
Looking for interesting roles... if you know someone that is looking for someone with my skills, feel free to point them in my direction :)
Tim McGuffin retweeted
⚡️We are hiring a Senior Applied AI Engineer for Cyber Defense Operations at @nvidia
You will work closely with cyber defense practitioners across detection, investigation, and response to identify where agentic AI can create meaningful operational value and help cyber defense move at machine speed where it matters. You will build and evaluate systems against real security workflows and ground truth, take the strongest approaches into production, and expand their use and capabilities as evidence supports it.
I am looking for someone with strong Applied AI experience who can move between applied research, experimentation, and engineering. You will evaluate models and agent architectures, specialize them where it adds value, and turn promising approaches into capabilities that work reliably at scale. You will use MLOps best practices to take what proves out into production and continuously improve it.
We take an open, interoperable, multi-model approach across NVIDIA AI technologies, open-weight and frontier models, and strategic partner capabilities. We choose the right approach for the problem, use what works, adapt where needed, and build where meaningful gaps remain 💚.
NVIDIA is a place where talented people come to do their life’s work. If this is the kind of challenge you want to take on while helping shape a broader, open and secure cybersecurity and AI ecosystem, I would love to hear from you 🙌.
📎 Job Description: nvidia.wd5.myworkdayjobs.com…
Tim McGuffin retweeted
My team (Threat Research and Detection Engineering) is hiring for three remote security roles at @elastic.
🤖AI Security - Principal Security Research Engineer I
🍎macOS / Container Security - Senior Security Research Engineer
📊Machine Learning - Principal Security ML Research Engineer I
If you are interested and have deep technical security expertise and a background in any of the above, feel free to reach out for details!
Tim McGuffin retweeted
I’m looking for a Security Researcher based in the US with hands-on experience in AD, Entra ID, and the ability to vibe code their way through solving problems. Strong communication skills and the willingness to take initiative is required for this role. ats.rippling.com/netwrix-cor…
Tim McGuffin retweeted
contentPolicy: FoR EDucATIONaL PUrPOSeS OnLY
👛🪵: github.blog/changelog/2026-0…
Tim McGuffin retweeted
Hey at least one but maybe 2 Cloud Engineer roles open at $dayjob - DM for details.
High points: AWS, GCP, ArgoCD, Terraform, heavy automation and AI push. Plenty of meaty work to do. Seek and destroy toil and tech debt.
100% remote, good comp.
Tim McGuffin retweeted
Exciting news! I'm hiring experienced vulnerability researchers @theZDI.
Do you love VR, sharing your work, and want to run categories at Pwn2Own? Come work with us (remotely).
Apply here: trendmicro.wd3.myworkdayjobs…
Feel free to DM me if you have any questions.
Tim McGuffin retweeted
Excited to finally be able to tweet this: we're looking for a world class visionary to lead @AnthropicAI's cyberdefense research mission.
Leading Glasswing and our cyberdefense mission this year has been an honor. It's now clear we need to scale up our ambition to help defend the world.
Done well, Glasswing and Mythos will look like a small first step. Claude is + will be one of the world's best security researchers -- what should we do with that? What should we research?
We're looking for a visionary, senior lead -- someone that can see past normal cybersecurity into the model-driven world beyond it. This is a senior position at Anthropic, and this person is a unicorn.
You will have a team of already world-class researchers that produced the work on Mythos vulns & exploits, n-days, attacks on networks, and our cyber evals. We have started working on new research we'll share soon.
This will be a massive lever on how AGI goes. Cyber will probably continue to drive the AI security and policy conversation. And we need cybersecurity in a world of extremely powerful models.
Link below.
Tim McGuffin retweeted
Our team (Platform Security Engineering) at @AnthropicAI is hiring for a few different positions/responsibilities: Offensive (job-boards.greenhouse.io/ant…), Architecture (job-boards.greenhouse.io/ant…), OS Kernel (job-boards.greenhouse.io/ant…) and BMC (job-boards.greenhouse.io/ant…). Come join @matrosov , myself and other awesome folks. Reach out if you have questions.
Tim McGuffin retweeted
My team is hiring platform security auditors. This is a strategic role supporting firmware and hardware security assessments, often working with limited documentation and relying on blackbox binary analysis to understand system internals, find vulnerabilities, and contribute to internal automation and tooling.
This is not a typical offensive security research role. You’ll be deeply involved in defining security architecture, exposing risk gaps, and making threat models match reality. It’s a rare opportunity to influence the future of AI infrastructure and the hardware behind it.
If this sounds like you, shoot me a DM or apply using the link below.
job-boards.greenhouse.io/ant…
hackerjeopardy.com/
Team signups open tomorrow. Shhhhhhh
Tim McGuffin retweeted
It’s that time again! I got some open job reqs to hire more Red Teamers at OCC! 🤓🙌
Senior red team position: theocc.wd5.myworkdayjobs.com…
Mid-level red team position: theocc.wd5.myworkdayjobs.com…
Tim McGuffin retweeted
I co-founded pfSense. For the last year I've been building its successor.
If you run pfSense today, you already know the reasons to look around: development you can't influence, a CE edition that feels like an afterthought, FreeBSD driver roulette on modern hardware, and a config workflow where one bad apply on a remote box means a drive.
nfSensei is my answer. Built from scratch in Rust, on Linux, and designed around the things pfSense users actually complain about.
Your config.xml imports. There's an importer that reads your pfSense config, shows you exactly what maps over and what needs attention, then applies it. You don't start from zero.
You can't brick it from the couch. Changes stage as a candidate, diff before apply, validate through the real engines before anything is written, and auto-roll-back if you don't confirm in time. If a config ever fails at boot, the box falls back to the last good one on its own.
The hardware works. Linux base means modern NICs and drivers just work — and the fast path compiles your rules to XDP at 40Gbps.
Automation is native, not scraped. Everything the UI does is a documented API call — about 1,140 of them, with a built-in explorer. Your Ansible finally gets a real interface.
The VPNs are current. WireGuard, IPsec, Tailscale, and self-hosted mesh — your own control plane, your keys — plus post-quantum key exchange where it counts.
The experimental stuff has its own wing. Thirty-plus Labs features behind toggles: WAN bonding that fuses multiple cheap uplinks through a $5 VPS into one resilient pipe, per-flow SLA telemetry with tamper-evident audit chains, GeoDNS that steers traffic by live RTT and load, application-aware QoS, config push to a whole fleet of remote nodes, and an AI assistant on the box that reads your actual interfaces and logs using local models. Toggles are per-browser and can't touch your running config — flip things on, break them, tell me about it. Oh, and there is much more to mention here!
Self-hosted, on your hardware, no cloud account, no subscription.
It's NOW IN ACTIVE BETA (previously alpha) with about 40 testers, and bug reports typically get fixed in days. I want more people who know what pfSense does well and can tell me exactly where nfSensei falls short.
If you are interested in testing please email me: sullrich@gmail.com. Tell me about your pfSense setup and I'll get you access.
Note: Affiliates and employees of Netgate are not invited.