root@rootreap3r_
$ whoami --verbose [ok] target identified

RootReap3r.

Joshua Urianza — AI Security Engineer specializing in LLM/agentic threat modeling, prompt-injection defense, and red-team scenario design, with a track record of discovering zero-days missed by enterprise tooling via manual exploit analysis. 10+ years securing nuclear C2, SAP/TEMPEST, and federal cloud environments at the TS/SCI level. M.S. AI candidate at Georgia Tech, researching adversarial robustness in agentic systems.
TS/SCI Active Clearance 10+ yrs DoD & AI Security M.S. AI Candidate — Georgia Tech Adversarial Prompting Since Mid 2022 One of the First AI-to-AI Warfare Researchers · Since 2022 AI Red-Teamer / AI Security Engineer — Ghostveli LLC
2,700+
TS-SAP assessments
416
security audits (Unclass–Top Secret)
100+
jailbreak / prompt-injection vulns exploited
<2min
C2 containment (from hours)
$147B
gov't program accredited (full ATO)
0
attributable incidents
Joshua Urianza (RootReap3r), security engineer
scope of work

Focus areas

ADVERSARIAL

Nation-state TTP attack engine

Built a red team engine auto-generating live attack scenarios from nation-state TTPs via MITRE ATT&CK/ATLAS, compressing adversary emulation cycles from weeks to hours.

PROTOCOL

RAG & MCP exploitation research

Red-teamed multi-modal RAG pipelines and MCP exploitation chains on nuclear-classified infrastructure; hardened findings into enforceable governance controls.

RESEARCH

TS/SAP vulnerability discovery

Surfaced previously unknown TS/SAP vulnerabilities through adversarial analysis beyond automated tooling, converting findings into IR tabletop scenarios to close gaps before nation-state exploitation.

GOVERNANCE

NC3 / nuclear ATO authorship

Authored ATO packages (~2,500 controls, SCTMs, SSPs) as Lead ISSO for Sentinel and Nuclear Command & Control programs. Led accreditation lifecycle across 10 packages for a $147B government program, mapping artifacts against all 20 NIST Rev 5 control families to achieve full ATO.

track record

Experience

Jul 2026 — Present

AI Red-Teamer / AI Security Engineer (Contract)

Ghostveli LLC
  • Exploited 100+ direct and cross-domain prompt-injection/jailbreak vulnerabilities across client LLM-integrated products within the first week, validated and scored via structured red-team taxonomy.
  • Built and deployed a multi-tenant AI chat widget embeddable on any site in <30 min, with production-grade security: CORS allowlisting, prompt-injection screening, XSS-safe rendering, CSRF protection, timing-safe auth.
  • Surfaced MCP tool-poisoning, schema injection, and cross-server privilege escalation via over-privileged server exploitation across client AI tool infrastructure.
Oct 2022 — Jul 2026

Senior Cybersecurity Engineer

Accenture Federal Services
  • Conducted adversarial security impact assessments on 2,700+ deliverables across software, hardware, networks, and AI/ML systems for a $147B TS/SAP cloud program, certifying risk disposition through malware analysis and vulnerability scanning.
Oct 2020 — Oct 2022

Security Program Manager

DS&S
  • Ran adversarial assessments across physical, INFOSEC, COMSEC, and cyber controls protecting $41M+ in CNWDI/DOE Restricted Data across two SAP/TEMPEST vaults, closing every exploitable gap found.
Mar 2020 — Oct 2020

Cyber Automation Lead

Sebastian Tech Solutions (DISA)
  • Built PowerShell/Python automation for account remediation and IR triage, cutting escalation decision time on leakage/compromise cases from minutes to seconds across DISA, White House, and Pentagon.
Apr 2018 — Mar 2020

Cyber Investigations Lead

Netflix
  • Led response to the 2019 credential-stuffing campaign compromising 900+ accounts, correlating device/IP/geolocation/VPN signals to restore 100% of accounts to original owners.
Mar 2015 — Apr 2018

Incident Response Lead

The Results Company
  • Advanced from help desk analyst to IR Lead, resolving 10,264 tickets and coordinating a multi-person IR team while sustaining a 96% stakeholder satisfaction scorecard.
builds

Projects

PHANTOM

AI-Powered Active Defense & Threat-Hunting Platform

Multi-agent active-defense platform using ML-based C2 beacon detection, passive attribution (geolocation, JA3, threat-intel), confidence-gated response, and cryptographic chain-of-custody evidence; shipped 105 passing tests and one-command FBI/CISA report generation (STIX 2.1, IOC).

ML beacon detectionJA3 / ASN attributionSTIX 2.1105 tests
recon-sweep

LLM Safety-Evaluation Harness

Red-team harness replacing self-graded LLM safety scoring with deterministic pass/fail gates (canary extraction, PII regex, injection detection) and an advisory-only LLM judge calibrated against a golden set, aligned to NIST AI RMF MEASURE/MANAGE, with a code-enforced allowlist immune to prompt-injection scope escape. Read the technical breakdown →

NIST AI RMFcanary / PII gatesallowlist isolation
RMF-AI-COPILOT

AI-Driven NIST 800-53 Rev 4→5 Migration Pipeline

Pipeline generating SCTM, eMASS export, and POA&M items from SSP content, grounding every AI judgment against the full 1,189-entry NIST Rev 5 catalog; provider-agnostic (Anthropic/OpenAI/Bedrock GovCloud), deployable air-gapped/NIPR with zero code changes.

NIST 800-53 Rev 5eMASS / SCTMair-gappedGovCloud
AI IR Tabletop

Adversarial LLM Incident-Response Tabletop Engine

Self-contained engine where an LLM plays a state-consistent threat actor across 23 scenarios and 9 MITRE-mapped APT profiles, with attacker/grader roles split across separate API passes and offline .docx after-action reports.

23 scenarios9 APT profiles.docx AAR
essays

Writing

2026-08-11

My First Week in Professional AI Red Teaming: What Nobody Tells You

Field notes on an unexpectedly diverse team, exploiting 100+ vulnerabilities in a week, and a recognition gap around obfuscated prompt injection — with two rewritten examples showing a real finding versus one that isn't.

2026-08-01

Building recon-sweep: A Scope-Gated Harness for Agentic AI Red Teaming

Inside recon-sweep's architecture — code-level scope-gated pentesting and falsifiable, canary/PII/injection-gated AI evaluation instead of LLM self-grading.

2026-07-28

Before ChatGPT: The First AI Jailbreak Community Nobody Talks About

A firsthand account of adversarial prompting against Midjourney's content filter months before ChatGPT's "DAN" prompts — and why keyword/semantic-matching guardrails still fail the same way today.

background

Education & Awards

In Progress

M.S. Artificial Intelligence · Georgia Institute of Technology

In progress (part-time). Research: adversarial robustness & red-teaming of LLMs and agentic systems.

Completed

B.A.S. Cyber Operations, Defense & Forensics · University of Arizona

NSA Center of Academic Excellence in Cyber Operations; malware reverse engineering, digital forensics.

Awards

Security Team of the Year · Air Force Nuclear Weapons Center

Also: Minuteman III Personnel Award, ICBM Personnel Award.

certification path

Interactive certification roadmap

Click a node. Gold = completed, purple = in progress. Concept-based progression by rarity, domain, and offensive vs. defensive focus.

Select a node

Click any certification above to view domain alignment, rarity, and offensive/defensive weighting.

Deciding which cybersecurity certification to pursue next? See the full interactive security certification roadmap — a concept-based breakdown of certs by rarity, domain, and offensive vs. defensive focus.

stack

Tooling & frameworks

MITRE ATLAS / ATT&CK NIST 800-53 Rev. 4 Metasploit Cobalt Strike / Sliver Mimikatz / BloodHound Python PowerShell Sysmon / Zeek / auditd STIX 2.1 Federal Cloud (Azure/AWS/GCP) ACAS SOAR

certs  SecAI+ (Beta Passer) · CASP+ · PenTest+ · Security+ · PWPE (<100 holders worldwide) · PNPT · eCPPTv3

in progress  COAE (HTB AI Red Teaming)

reach out

Contact

$ cat contact.txt