Offensive security Eagle Mountain, Utah portfolio.harvestrangelabs.com

Mitch O'Donnell

Lead AI Red Team / Threat Emulation Engineer · OutSystems

I lead threat emulation where the point of the exercise is a decision: what to fix, what to detect, and what to stop treating as covered. The work runs through red team, purple team, product security, cloud, and AI.

LinkedIn GitHub
01

Outcomes

Three places the work changed what the organization did next.

02

Practice

Select a practice to filter the experience below. Select it again to clear.

03

Experience

Open a role for the record. The PDF includes every role, whether or not it is expanded on screen.

OutSystems

2021 — Present · Eagle Mountain, UT / Remote

Low-code platform for building, deploying, and managing enterprise applications and AI agents.

Apr 2026 — Present Lead AI Red Team / Threat Emulation Engineer Threat emulation for AI-driven exposure
  • Lead threat emulation and adversary simulation aimed at how the organization is exposed to AI-driven attacks.
  • Built testing methods and simulation harnesses for model behavior, security boundaries, and attack potential in AI-enabled software.
  • Automated a path from SAST and DAST through validation and adversary simulation so a finding can be judged as an attack chain, not a ticket.
  • Stood up large-scale ingestion and analysis of Forge models across O11 and ODC, covering third-party and community code that had not been visible before.
  • Used those findings to show how individual weaknesses combine, and built repeatable simulations around them to measure model behavior, control effectiveness, and defensive response.
  • Defined metrics and telemetry for the simulations so posture changes are something you can track.
  • Partnered with Security Operations on Atomic Red Team-style tests for emerging AI threats, and with Application Security, Cloud Security, Engineering, and Product Security to turn results into preventative and detective controls.
Jul 2025 — Apr 2026 Team Lead, Application Security Strategy, priority, and engineering engagement
  • Technical lead for Application Security, with management-level scope across strategy, prioritization, and execution.
  • Cleared organizational and technical blockers so engineers could run vulnerability management, threat modeling, secure development, and product security work.
  • Coordinated AppSec across engineering and with the SOC, Cloud Security, Product Security, and leadership.
  • Tightened how vulnerabilities are identified, validated, prioritized, and explained.
  • Brought offensive findings into the development lifecycle so teams hit the issues earlier.
Oct 2024 — Jul 2025 Lead Red Team Security Engineer, Product Security Red team inside the product lifecycle
  • Drove secure-by-design work by keeping red team exercises inside the product lifecycle.
  • Worked with Application Security and Cloud Security on assessments across Kubernetes, APIs, thick clients, and web applications in multi-cloud environments.
  • Ran longer adversary simulations that exposed systemic authentication and authorization weaknesses early enough to fix during development.
  • Turned technical risk into product changes, treating security as part of what the product can claim.
Feb 2023 — Oct 2024 Lead Red Team Engineer, Advisor Executive and engineering advisory
  • Advised executive stakeholders and engineering leaders.
  • Led red team advisory engagements, logged findings in Jira, published reports through Ghostwriter, and walked product teams through mitigation.
  • Used risk-based consultation to influence roadmaps and line security work up with compliance and business requirements.
  • Framed design and architecture risks — including ones that could hit revenue or operations — as decisions leadership could make.
Apr 2022 — Feb 2023 Lead Red Team Security Engineer, Security Architect Tooling and measurable outcomes
  • Architected offensive security tooling and the reporting around red team outcomes.
  • Automated engagement reports with Ghostwriter and Vectr so quarterly and annual cycles were data, not a slide reconstructed from memory.
  • Delivered KPIs that tied engagement outcomes to potential financial impact for security investment decisions.
Mar 2021 — Apr 2022 Red Team Security Engineer, Cloud Security Full-scope cloud operations
  • Ran full-scope cloud red team operations and built the offensive infrastructure behind them.
  • Led adversary emulation with MITRE ATT&CK, kept threat models and kill chains in Lucidchart, and logged engagements in Vectr.
  • Exercised custom tooling in Python, Bash, PowerShell, and C++ against EC2, EKS, ECR, and containers.
  • Demonstrated durable access through misconfigurations in IAM, build pipelines, and container registries on AWS and Azure.
  • Ran phishing and follow-on exercises that tested response, lateral movement, and credential abuse. The work supported MFA for all users.
  • Used AWS Secrets Manager, Azure Key Vault, Route 53, and Azure DevOps so exercises resembled production rather than a lab diagram.
  • Briefed engineers, developers, and executives, and worked with the SOC, DevSecOps, Application Security, and vendors on what to harden.
  • Covered web assessment areas including injection, cross-site scripting, cross-site request forgery, cache poisoning, and server-side request forgery.
  • Found unprotected developer credentials in GitHub repositories. A controlled simulation against a legacy platform made the case for real-time event logging.

Pure Storage

2016 — 2021 · Lehi, UT / Remote

All-flash data storage hardware and software.

2020 — 2021 Product Security Engineer, Red Team Product, network, and purple team
  • Led network and application testing across on-premises, AWS, and Azure, and reviewed threat models with development teams.
  • Staged attacks against company products and ran purple team exercises on company infrastructure using MITRE ATT&CK.
  • Tested web applications against the OWASP Top 10, including injection and input handling, and checked REST APIs and restricted shells for privilege mistakes.
  • Used external exposure search to find company devices that were reachable when they should not have been.
  • A successful compromise of code repositories led about 2,000 engineers to move exclusively to GitHub.
  • Identified a critical vulnerability in a new Azure offering. It became the basis for a network redesign and for keeping an in-house red team.
2018 — 2020 Escalation Engineer and Red Team Severity, labs, and product trust
  • Primary contact for escalated software issues, judging severity from storage, switch, and host logs, then writing knowledge-base entries and handing fixes to developers.
  • Patched production bugs with Python and Bash.
  • As lab administrator, wrote a Python program that replicated host, storage, switch, and array environments and cut reproduction time from about a day to about 30 minutes.
  • Resolved security issues in storage products that showed up in customer trust, not only in a bug count.
2017 — 2018 Technical Support Engineer 2 Hosts, switches, and support tooling
  • Supported Linux, RHEL, CentOS, Fedora, ESXi, vSphere, and Windows, plus Brocade and Cisco switching.
  • Wrote Python and Bash tools that automated troubleshooting for the support engineering team.
2016 — 2017 Technical Support Engineer 1 Startup-phase array support
  • Joined during the startup phase, upgrading arrays with as little downtime as possible and working tickets across full shelves, timeouts, BIOS resets, failed SSDs, machine checks, deduplication, and failing DIMMs.
  • Guided technicians through hardware and controller replacement, including migrations of petabytes of data.

Earlier

2010 — 2016 · Utah

Hosting operations, then retail systems, before the security roles.

2015 — 2016 Cloud and Technical Support Tier 2 Robert Half, retained by Verio · Orem, UT
  • Configured and repaired shared and standalone hosting: LAMP stacks, certificates, CMS platforms, DNS zones, and access rules.
  • Helped small businesses whose sites had been compromised: identified how the site was reached, restored a known-good copy, and showed them how to harden what remained.
  • Assisted the Unix, Linux, and Windows transition after NTT America acquired Verio, across as many as 5,000 hosted sites.
2010 — 2015 Systems Support Analyst, SME, and QA / UAT Guitar Center and Musician’s Friend · Draper, UT
  • Programming, quality assurance, and user-acceptance testing for the Guitar Center and Musician’s Friend sites. Reproduced bugs in QuickBase and Jira.
  • Worked Microsoft Dynamics AX issues that blocked order and sales processing.
Early career Technical Support Tier I Teleperformance · Lindon, UT
  • First-line technical support.
04

Kill chain

How an engagement moves from a hypothesis to evidence, a detection gap, and a decision. Phase notes are in progress.

Living document · notes in progress

Phase 01

Reconnaissance

What the engagement needs to learn, and what stays out of scope.

Notes forthcoming.

Phase 02

Weaponization

What capability gets prepared, and why it matches the objective.

Notes forthcoming.

Phase 03

Delivery

How the exercise reaches a control that has to respond.

Notes forthcoming.

Phase 04

Exploitation

What a successful condition looks like, and how it is proven.

Notes forthcoming.

Phase 05

Installation

What a foothold means for this engagement, and how it is contained.

Notes forthcoming.

Phase 06

Command and Control

How operator communication is bounded, logged, and torn down.

Notes forthcoming.

Phase 07

Actions on Objectives

What done means, which evidence is kept, and who receives the decision.

Notes forthcoming.

06

Training

What is already public. The full certification list is available on request.

Security

Courses on the public record

  • Offensive Pentesting Learning Path — TryHackMe, Dec 2021
  • Advanced Malware Analysis: Redux — Cybrary, Feb 2021
  • Advanced Penetration Testing — Cybrary, Feb 2020
  • Offensive Penetration Testing — Cybrary, Jan 2020

Engineering

Languages

  • Go — Sololearn, Jul 2022
  • Python 3, PHP, SQL, JavaScript, jQuery — Sololearn, 2017–2018
  • Daily tooling across Go, Python, PowerShell, Bash, and C++
07

Contact

Eagle Mountain, Utah. Red team, purple team, product security, and AI threat emulation.